CVE-2024-1743: WooCommerce Customers Manager < 29.8 - Reflected XSS
The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1743?
CVE-2024-1743 is considered a high severity vulnerability due to its potential impact on high privilege users.
How do I fix CVE-2024-1743?
To fix CVE-2024-1743, upgrade the WooCommerce Customers Manager plugin to version 29.8 or later.
What type of vulnerability is CVE-2024-1743?
CVE-2024-1743 is a Reflected Cross-Site Scripting vulnerability.
Who is affected by CVE-2024-1743?
CVE-2024-1743 affects users of the WooCommerce Customers Manager plugin prior to version 29.8.
What consequences can arise from CVE-2024-1743?
Exploiting CVE-2024-1743 could allow an attacker to execute malicious scripts in the context of an admin user's session.