CVE-2024-39666: WordPress WooCommerce plugin <= 9.1.2 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 9.1.2.
Affected Software
2 affected components
Automattic WooCommerce<=9.1.2
WordPress WooCommerce<=9.1.2
Remediation
Information
Update to 9.1.3 or a higher version.
Event History
Aug 18, 2024
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-39666?
CVE-2024-39666 has a high severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2024-39666?
You can fix CVE-2024-39666 by updating WooCommerce to version 9.1.3 or later.
3
What systems are affected by CVE-2024-39666?
CVE-2024-39666 affects versions of WooCommerce from n/a through 9.1.2.
4
What type of vulnerability is CVE-2024-39666?
CVE-2024-39666 is classified as an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as cross-site scripting (XSS).
5
Is CVE-2024-39666 easy to exploit?
Yes, CVE-2024-39666 can be easily exploited, allowing attackers to inject malicious scripts into web pages.