CVE-2024-44046: WordPress Themify plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability
Published Oct 6, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify – WooCommerce Product Filter themify-wc-product-filter allows Stored XSS.This issue affects Themify – WooCommerce Product Filter: from n/a through <= 1.5.1.
Affected Software
3 affected components
Themify WooCommerce Product Filter<=1.5.1
WordPress Themify plugin<=1.5.1
Themify Woocommerce Product Filter Wordpress<1.5.2
Remediation
Information
Update to 1.5.2 or a higher version.
Event History
Oct 6, 2024
CVE Published
via MITRE·11:48 AM
Data Sourced
via MITRE·11:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-44046?
CVE-2024-44046 has a medium severity rating due to the potential for stored XSS attacks.
2
How do I fix CVE-2024-44046?
To fix CVE-2024-44046, upgrade Themify – WooCommerce Product Filter to version 1.5.2 or later.
3
What types of vulnerabilities does CVE-2024-44046 introduce?
CVE-2024-44046 introduces a stored Cross-site Scripting (XSS) vulnerability.
4
What versions of Themify are affected by CVE-2024-44046?
CVE-2024-44046 affects Themify – WooCommerce Product Filter versions up to and including 1.5.1.
5
What are the potential consequences of CVE-2024-44046?
Exploitation of CVE-2024-44046 could allow attackers to execute arbitrary JavaScript in users' browsers.