CVE-2024-4455
YITH WooCommerce Ajax Search <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2024-4455 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 24, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 24, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WooCommerce Ajax Search Plugin for WordPressBrowse YITH / WooCommerce Ajax Search Plugin for WordPress | VulnCheck | Version data not supplied | |
YITH WooCommerce Ajax SearchBrowse yithemes / YITH WooCommerce Ajax SearchDefault status: unaffected | CVE List | Through 2.4.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHYITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site ScriptingCVSS 7.2
The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'queryString' parameter in the REST API endpoint /ywcas/v1/register in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping.
Impact
Attackers can execute arbitrary scripts in users' browsers, potentially leading to session hijacking, defacement, or redirection.
Remediation
Update YITH WooCommerce Ajax Search plugin to version 2.4.1 or later.
Source: ProjectDiscovery