CVE-2024-35728: WordPress Product Addons & Fields for WooCommerce plugin <= 32.0.20 - Content Injection vulnerability
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce allows Code Inclusion.This issue affects PPOM for WooCommerce: from n/a through 32.0.20.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35728?
CVE-2024-35728 has been classified as a critical severity vulnerability due to its potential for code inclusion.
How do I fix CVE-2024-35728?
To fix CVE-2024-35728, update the Themeisle PPOM for WooCommerce to version 32.0.21 or later.
What systems are affected by CVE-2024-35728?
CVE-2024-35728 affects Themeisle PPOM for WooCommerce versions from n/a through 32.0.20.
What type of vulnerability is CVE-2024-35728?
CVE-2024-35728 is categorized as an Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability.
Can CVE-2024-35728 lead to remote code execution?
Yes, CVE-2024-35728 can potentially lead to remote code execution if exploited by an attacker.