CVE-2024-6076: WP eStore < 8.5.5 - Reflected XSS in Category Editing
Published Jul 15, 2024
·Updated
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
Tipsandtricks-hq Wp Estore Wordpress<8.5.5
Event History
Jul 15, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6076?
CVE-2024-6076 is classified as a high-severity vulnerability due to its potential impact on high privilege users.
2
How do I fix CVE-2024-6076?
To fix CVE-2024-6076, update the wp-cart-for-digital-products WordPress plugin to version 8.5.5 or later.
3
What type of vulnerability is CVE-2024-6076?
CVE-2024-6076 is a Reflected Cross-Site Scripting (XSS) vulnerability.
4
Who is primarily affected by CVE-2024-6076?
CVE-2024-6076 primarily affects high privilege users, such as administrators of the WordPress site.
5
What causes CVE-2024-6076?
CVE-2024-6076 is caused by the failure to sanitize and escape a parameter before it is output on the page.