First published: Sun Oct 20 2024(Updated: )
: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WPFactory EU/UK VAT Manager for WooCommerce allows Cross-Site Scripting (XSS).This issue affects EU/UK VAT Manager for WooCommerce: from n/a through 2.12.14.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpfactory EU/UK VAT Manager for WooCommerce WordPress | <3.0.0 |
Update to 3.0.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-44061 is classified as medium due to its potential to enable cross-site scripting (XSS) attacks.
To fix CVE-2024-44061, update the EU/UK VAT Manager for WooCommerce plugin to version 2.12.15 or later, which addresses the XSS vulnerability.
CVE-2024-44061 affects EU/UK VAT Manager for WooCommerce versions from n/a through 2.12.14.
CVE-2024-44061 is an improper neutralization of script-related HTML tags in a web page, leading to a cross-site scripting (XSS) vulnerability.
Users of the EU/UK VAT Manager for WooCommerce plugin on WordPress are impacted by CVE-2024-44061 if they are using the affected versions.