CVE-2024-37943: WordPress YITH WooCommerce Ajax Product Filter plugin <= 5.1.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Ajax Product Filter yith-woocommerce-ajax-navigation.This issue affects YITH WooCommerce Ajax Product Filter: from n/a through <= 5.1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37943?
CVE-2024-37943 is classified as a high-severity reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-37943?
To fix CVE-2024-37943, upgrade the YITH WooCommerce Ajax Product Filter plugin to version 5.1.1 or later.
What is the impact of CVE-2024-37943?
The impact of CVE-2024-37943 allows attackers to execute arbitrary scripts in the context of the user’s session, potentially leading to data theft or session hijacking.
Which versions of YITH WooCommerce Ajax Product Filter are affected by CVE-2024-37943?
CVE-2024-37943 affects all versions of YITH WooCommerce Ajax Product Filter up to and including version 5.1.0.
Is user input involved in CVE-2024-37943?
Yes, CVE-2024-37943 involves improper neutralization of user input during web page generation, leading to XSS.