CVE-2024-7846: YITH WooCommerce Ajax Search < 2.7.1 - Contributor+ Stored XSS
Published Sep 23, 2024
·Updated
YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.
Affected Software
2 affected components
YITH WooCommerce Ajax Search<2.7.1
YITHEMES Yith Woocommerce Ajax Search Wordpress<2.7.1
Event History
Sep 23, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-7846?
CVE-2024-7846 is classified as a high-severity XSS vulnerability.
2
How do I fix CVE-2024-7846?
To mitigate CVE-2024-7846, update YITH WooCommerce Ajax Search to version 2.7.2 or later.
3
Who is affected by CVE-2024-7846?
CVE-2024-7846 affects users of YITH WooCommerce Ajax Search versions up to 2.7.1.
4
What type of vulnerability is CVE-2024-7846?
CVE-2024-7846 is an XSS (Cross-Site Scripting) vulnerability caused by insufficient sanitization.
5
What can attackers do with CVE-2024-7846?
Attackers with Contributor+ permissions can inject arbitrary scripts through the vulnerability in CVE-2024-7846.