CVE-2024-35680: WordPress YITH WooCommerce Product Add-Ons plugin <= 4.9.2 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through <= 4.9.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35680?
CVE-2024-35680 is classified as a critical vulnerability due to its potential for code injection in affected systems.
How do I fix CVE-2024-35680?
To fix CVE-2024-35680, you should update YITH WooCommerce Product Add-Ons to version 4.9.3 or later.
What version of YITH WooCommerce Product Add-Ons is affected by CVE-2024-35680?
CVE-2024-35680 affects all versions of YITH WooCommerce Product Add-Ons prior to 4.9.3.
What type of vulnerability is CVE-2024-35680?
CVE-2024-35680 is an injection vulnerability caused by improper neutralization of special elements in output.
Can CVE-2024-35680 affect my website?
Yes, if you are using a version of YITH WooCommerce Product Add-Ons below 4.9.3, your website is at risk due to CVE-2024-35680.