CVE-2024-7846

CVE-2024-7846: YITH WooCommerce Ajax Search < 2.7.1 - Contributor+ Stored XSS

Vendor Unknown
Product YITH WooCommerce Ajax Search
Published September 23, 2024
Last update September 23, 2024

CVSS base score

What the vulnerability does

01Description

YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.

Key dates

02Disclosure timeline

September 23, 2024 CVE published
September 23, 2024 Record updated