CVE-2024-8499: Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.0.3 - Reflected Cross-Site Scripting via render_review_request_notice
The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘renderreviewrequestnotice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8499?
CVE-2024-8499 is considered medium severity due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2024-8499?
To fix CVE-2024-8499, update the Checkout Field Editor for WooCommerce plugin to version 2.0.4 or higher.
What is affected by CVE-2024-8499?
CVE-2024-8499 affects all versions of the Checkout Field Editor for WooCommerce plugin up to and including version 2.0.3.
What type of vulnerability is CVE-2024-8499?
CVE-2024-8499 is classified as a reflected cross-site scripting (XSS) vulnerability.
What is the impact of CVE-2024-8499?
The impact of CVE-2024-8499 includes the potential for an attacker to execute arbitrary JavaScript in the context of the user’s browser.