The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
History

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Prontotools
Prontotools woo Cart Count Shortcode
Weaknesses CWE-79
CPEs cpe:2.3:a:prontotools:woo_cart_count_shortcode:*:*:*:*:*:wordpress:*:*
Vendors & Products Prontotools
Prontotools woo Cart Count Shortcode

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Wed, 26 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Title WooCommerce Cart Count Shortcode < 1.1.0 - Contributor+ XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-02-26T06:00:06.364Z

Updated: 2025-02-26T14:47:58.291Z

Reserved: 2024-10-30T19:52:49.399Z

Link: CVE-2024-10563

cve-icon Vulnrichment

Updated: 2025-02-26T14:41:59.944Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-26T13:15:35.443

Modified: 2025-05-20T19:59:02.140

Link: CVE-2024-10563

cve-icon Redhat

No data.