CVE-2024-2263: WooCommerce Product Filter < 1.4.4 - Reflected XSS
Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2263?
CVE-2024-2263 has a high severity level due to its potential to allow reflected cross-site scripting attacks against high privilege users.
How do I fix CVE-2024-2263?
To fix CVE-2024-2263, update the Themify WordPress plugin to version 1.4.4 or later that includes the necessary sanitization and escaping fixes.
Who is affected by CVE-2024-2263?
CVE-2024-2263 affects users of the Themify WordPress plugin and the WooCommerce Product Filter plugin versions prior to 1.4.4.
What type of attack is associated with CVE-2024-2263?
CVE-2024-2263 is associated with reflected cross-site scripting, which can exploit vulnerabilities in web applications.
What versions of the Themify plugin are vulnerable to CVE-2024-2263?
All versions of the Themify WordPress plugin prior to 1.4.4 are vulnerable to CVE-2024-2263.