First published: Tue Jul 09 2024(Updated: )
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a through 8.9.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Automattic WooCommerce Square | <=8.9.2 | |
WordPress WooCommerce plugin | <=8.9.2 |
Update to 9.0.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35777 has been classified as a content spoofing vulnerability.
To fix CVE-2024-35777, upgrade WooCommerce to version 8.9.3 or later.
CVE-2024-35777 affects WooCommerce versions from n/a through 8.9.2.
CVE-2024-35777 can facilitate content spoofing attacks due to improper neutralization of special elements.
Users running affected versions of Automattic WooCommerce or the WordPress WooCommerce plugin are impacted by CVE-2024-35777.