CVE-2024-35777: WordPress WooCommerce plugin <= 8.9.2 - Content Injection vulnerability
Published Jul 9, 2024
·Updated
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a through 8.9.2.
Affected Software
2 affected components
Automattic WooCommerce<=8.9.2
WordPress WooCommerce plugin<=8.9.2
Remediation
Information
Update to 9.0.0 or a higher version.
Event History
Jul 9, 2024
CVE Published
via MITRE·09:57 AM
Data Sourced
via MITRE·09:57 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35777?
CVE-2024-35777 has been classified as a content spoofing vulnerability.
2
How do I fix CVE-2024-35777?
To fix CVE-2024-35777, upgrade WooCommerce to version 8.9.3 or later.
3
Which versions of WooCommerce are affected by CVE-2024-35777?
CVE-2024-35777 affects WooCommerce versions from n/a through 8.9.2.
4
What kind of attacks can CVE-2024-35777 facilitate?
CVE-2024-35777 can facilitate content spoofing attacks due to improper neutralization of special elements.
5
Who is impacted by CVE-2024-35777?
Users running affected versions of Automattic WooCommerce or the WordPress WooCommerce plugin are impacted by CVE-2024-35777.