CVE-2024-56265: WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Cross Site Scripting (XSS) vulnerability
Published Dec 31, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9.
Affected Software
2 affected components
wpweb WooCommerce PDF Vouchers<4.9.9
Wpwebelite Woocommerce Pdf Vouchers Wordpress<4.9.9
Remediation
Information
Update the WordPress WooCommerce PDF Vouchers plugin to the latest available version (at least 4.9.9).
Event History
Dec 31, 2024
CVE Published
via MITRE·10:14 AM
Data Sourced
via MITRE·10:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56265?
CVE-2024-56265 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How can I fix CVE-2024-56265?
To fix CVE-2024-56265, update the WPWeb WooCommerce PDF Vouchers plugin to version 4.9.9 or higher.
3
What version of WPWeb WooCommerce PDF Vouchers is affected by CVE-2024-56265?
CVE-2024-56265 affects versions of WPWeb WooCommerce PDF Vouchers prior to 4.9.9.
4
What impact does CVE-2024-56265 have on my website?
CVE-2024-56265 can allow an attacker to execute arbitrary JavaScript in the context of a user’s session.
5
Is CVE-2024-56265 a common vulnerability in WordPress plugins?
CVE-2024-56265 represents a common type of vulnerability found in WordPress plugins, particularly related to input validation.