CVE-2021-24974
Product Feed PRO for WooCommerce < 11.0.7 - Subscriber+ Settings Update to Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping.
El plugin Product Feed PRO for WooCommerce de WordPress versiones anteriores a 11.0.7, no dispone de autorización y comprobación CSRF en algunas de sus acciones AJAX, permitiendo que cualquier usuario autenticado las llame, lo que podría conllevar un problema de tipo Cross-Site Scripting Almacenado (que será desencadenado en el panel de administración) debido a una falta de escape
The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorization and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-12-23 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/8ed549fe-7d27-4a7a-b226-c20252964b29 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adtribes Search vendor "Adtribes" | Product Feed Pro For Woocommerce Search vendor "Adtribes" for product "Product Feed Pro For Woocommerce" | < 11.0.7 Search vendor "Adtribes" for product "Product Feed Pro For Woocommerce" and version " < 11.0.7" | wordpress |
Affected
|