CVE-2024-6133: WP eStore < 8.5.6 - Reflected XSS in Customer Search
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6133?
CVE-2024-6133 has a medium severity rating due to its potential impact on high privilege users such as administrators.
How do I fix CVE-2024-6133?
To fix CVE-2024-6133, update the wp-cart-for-digital-products plugin to version 8.5.6 or later.
What is CVE-2024-6133?
CVE-2024-6133 is a Reflected Cross-Site Scripting vulnerability in the wp-cart-for-digital-products WordPress plugin that allows attackers to inject malicious scripts.
Who is affected by CVE-2024-6133?
Users of the wp-cart-for-digital-products plugin before version 8.5.6 on WordPress are affected by CVE-2024-6133, particularly high privilege users.
What versions of the wp-cart-for-digital-products plugin are vulnerable to CVE-2024-6133?
Versions of the wp-cart-for-digital-products plugin prior to 8.5.6 are vulnerable to CVE-2024-6133.