CVE-2024-50448: WordPress YITH WooCommerce Product Add-Ons plugin <= 4.14.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through <= 4.14.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50448?
CVE-2024-50448 is classified as a medium severity vulnerability due to its ability to allow reflected cross-site scripting (XSS).
How do I fix CVE-2024-50448?
To fix CVE-2024-50448, upgrade YITH WooCommerce Product Add-Ons to version 4.14.2 or later.
What types of attacks are possible with CVE-2024-50448?
CVE-2024-50448 allows attackers to execute arbitrary JavaScript in the context of the victim's browser through reflected XSS attacks.
Which versions of YITH WooCommerce Product Add-Ons are affected by CVE-2024-50448?
CVE-2024-50448 affects all versions of YITH WooCommerce Product Add-Ons before 4.14.2.
Is CVE-2024-50448 a vulnerability in only YITH WooCommerce Product Add-Ons?
Yes, CVE-2024-50448 specifically affects the YITH WooCommerce Product Add-Ons plugin.