CVE-2024-37509: WordPress MakeCommerce for WooCommerce plugin <= 3.5.1 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jul 21, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maksekeskus AS MakeCommerce for WooCommerce allows Reflected XSS.This issue affects MakeCommerce for WooCommerce: from n/a through 3.5.1.
Affected Software
1 affected component
MakeCommerce Makecommerce For Woocommerce Wordpress<3.5.2
Remediation
Information
Update to 3.5.2 or a higher version.
Event History
Jul 21, 2024
CVE Published
via MITRE·07:18 AM
Data Sourced
via MITRE·07:18 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37509?
The severity of CVE-2024-37509 is classified as high due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2024-37509?
To fix CVE-2024-37509, update MakeCommerce for WooCommerce to version 3.5.2 or later.
3
What types of attacks can be executed using CVE-2024-37509?
CVE-2024-37509 can be exploited for reflected cross-site scripting (XSS) attacks.
4
Which versions of MakeCommerce for WooCommerce are affected by CVE-2024-37509?
CVE-2024-37509 affects versions of MakeCommerce for WooCommerce from n/a through 3.5.1.
5
What is the impact of CVE-2024-37509 on user data?
CVE-2024-37509 can allow attackers to execute scripts in the context of the user's session, potentially compromising user data.