CVE-2024-44061: WordPress EU/UK VAT Manager for WooCommerce plugin <= 2.12.14 - CSRF to Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EU/UK VAT Manager for WooCommerce eu-vat-for-woocommerce.This issue affects EU/UK VAT Manager for WooCommerce: from n/a through <= 2.12.14.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44061?
The severity of CVE-2024-44061 is classified as medium due to its potential to enable cross-site scripting (XSS) attacks.
How do I fix CVE-2024-44061?
To fix CVE-2024-44061, update the EU/UK VAT Manager for WooCommerce plugin to version 2.12.15 or later, which addresses the XSS vulnerability.
What versions are affected by CVE-2024-44061?
CVE-2024-44061 affects EU/UK VAT Manager for WooCommerce versions from n/a through 2.12.14.
What type of vulnerability is CVE-2024-44061?
CVE-2024-44061 is an improper neutralization of script-related HTML tags in a web page, leading to a cross-site scripting (XSS) vulnerability.
Who is impacted by CVE-2024-44061?
Users of the EU/UK VAT Manager for WooCommerce plugin on WordPress are impacted by CVE-2024-44061 if they are using the affected versions.