First published: Mon Dec 02 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Schwartz WP e-Commerce Style Email allows Reflected XSS.This issue affects WP e-Commerce Style Email: from n/a through 0.6.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP eCommerce | <=0.6.2 | |
WP eCommerce Style Email | <=0.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52462 is a reflected cross-site scripting (XSS) vulnerability, which can allow attackers to inject malicious scripts into web pages.
To fix CVE-2024-52462, update the WP e-Commerce Style Email plugin to version 0.6.3 or later.
CVE-2024-52462 affects users of the WP e-Commerce Style Email plugin from version n/a up to and including 0.6.2.
Attackers can exploit CVE-2024-52462 to execute arbitrary scripts in the context of the user's browser.
The active exploitation status of CVE-2024-52462 is not publicly documented, but it is advisable to apply the patch immediately.