CVE-2024-1679: Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce <= 3.4.6 - Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates
The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template and javascript label fields in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1679?
CVE-2024-1679 is classified as a moderate severity vulnerability due to its potential for Stored Cross-Site Scripting.
How do I fix CVE-2024-1679?
To fix CVE-2024-1679, update the Print Labels with Barcodes plugin to version 3.4.7 or later.
Which versions of the Print Labels with Barcodes plugin are affected by CVE-2024-1679?
All versions up to and including 3.4.6 of the Print Labels with Barcodes plugin are affected by CVE-2024-1679.
What types of input are vulnerable in CVE-2024-1679?
The template and javascript label fields are vulnerable to Stored Cross-Site Scripting in CVE-2024-1679.
Who is affected by CVE-2024-1679?
Any WordPress site using the affected versions of the Print Labels with Barcodes plugin is susceptible to CVE-2024-1679.