CVE-2024-27994
CVE-2024-27994 is a reflected XSS (Cross-Site Scripting) vulnerability in the YITH WooCommerce Product Add-Ons plugin. This vulnerability allows attackers to inject malicious scripts into web pages, potentially compromising user data and system integrity. Specifically, versions up to and including 4.5.0 of the YITH WooCommerce Product Add-Ons plugin are affected. While the CVSS score is 7.1 indicating high severity, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a relatively lower immediate risk compared to critical vulnerabilities. However, because this vulnerability is tagged as "In The Wild", its exploitable nature is already confirmed. Successful exploitation could lead to session hijacking, defacement of websites, or redirection of users to malicious sites. Website administrators using the YITH WooCommerce Product Add-Ons plugin should update to the latest version promptly to mitigate this security risk. Addressing this vulnerability reduces the attack surface and protects sensitive information.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.