5.4
CVE-2021-24974
- EPSS 0.21%
- Veröffentlicht 24.01.2022 08:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:06
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Product Feed PRO for WooCommerce <= 11.0.6 - Settings Update to Stored Cross-Site Scripting
The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping.
Mögliche Gegenmaßnahme
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce: Update to version 11.0.7, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
Version
[*, 11.0.7)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adtribes ≫ Product Feed Pro For Woocommerce SwPlatformwordpress Version < 11.0.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.433 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.