CVE-2024-6072
15.07.2024, 06:15
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Vendor | Product | Version |
---|---|---|
wordpress_plugin | wp-cart-for-digital-products | 𝑥 < 8.5.5 |
tipsandtricks-hq | wp_estore | 𝑥 < 8.5.5 |
𝑥
= Vulnerable software versions