CVE-2024-6074: WP eStore < 8.5.5 - Reflected XSS in Customer Editing
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6074?
CVE-2024-6074 is classified as a high severity vulnerability due to its potential impact on high privilege users.
How do I fix CVE-2024-6074?
To mitigate CVE-2024-6074, upgrade the wp-cart-for-digital-products WordPress plugin to version 8.5.5 or later.
What types of attacks are possible with CVE-2024-6074?
CVE-2024-6074 could be exploited to conduct Reflected Cross-Site Scripting attacks on site administrators.
Which versions of the wp-cart-for-digital-products plugin are affected by CVE-2024-6074?
CVE-2024-6074 affects all versions of the wp-cart-for-digital-products plugin before 8.5.5.
Who is most at risk from CVE-2024-6074?
Site administrators and users with high privileges are the most at risk from CVE-2024-6074.