CVE-2024-2278: WooCommerce Product Filter < 1.4.4 - Admin+ Stored XSS
Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2278?
CVE-2024-2278 has been classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2278?
To fix CVE-2024-2278, update the Themify WordPress plugin to version 1.4.4 or later.
Who is affected by CVE-2024-2278?
CVE-2024-2278 affects users of the Themify WordPress plugin and WooCommerce Product Filter plugin versions prior to 1.4.4.
What attack vector is associated with CVE-2024-2278?
CVE-2024-2278 allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks.
Is CVE-2024-2278 relevant in multisite setups?
Yes, CVE-2024-2278 is particularly concerning in multisite setups where unfiltered_html capability is disallowed.