CVE-2024-39652: WordPress WooCommerce PDF Vouchers plugin < 4.9.5 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39652?
CVE-2024-39652 is classified as a medium severity vulnerability due to the potential for reflected cross-site scripting.
How do I fix CVE-2024-39652?
To fix CVE-2024-39652, update the WPWeb Elite WooCommerce PDF Vouchers plugin to version 4.9.5 or later.
Which versions of WooCommerce PDF Vouchers are affected by CVE-2024-39652?
CVE-2024-39652 affects all versions of WPWeb Elite WooCommerce PDF Vouchers prior to version 4.9.5.
What type of vulnerability is CVE-2024-39652?
CVE-2024-39652 is an XSS (Cross-site Scripting) vulnerability related to improper neutralization of input during web page generation.
Who is affected by CVE-2024-39652?
Users of WPWeb Elite WooCommerce PDF Vouchers prior to version 4.9.5 are affected by CVE-2024-39652.