CVE-2024-10519

Source
https://cve.org/CVERecord?id=CVE-2024-10519
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10519.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-10519
Published
2024-11-23T09:39:10.641Z
Modified
2026-08-12T03:51:26.078653904Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Wishlist for WooCommerce: Multi Wishlists Per Customer PRO 3.0.8 - 3.1.2 - Reflected Cross-Site Scripting via wtab Parameter
Details

The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' parameter in versions 3.0.8 to 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Note: Only WordPress installations with versions of PHP <=7.4 are affected by this vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10519.json",
    "cna_assigner": "Wordfence"
}
References

Affected packages

Git / github.com/wpcodefactory/wish-list-for-woocommerce

Affected ranges

Type
GIT
Repo
https://github.com/wpcodefactory/wish-list-for-woocommerce
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:wpfactory:wishlist_for_woocommerce:*:*:*:*:*:wordpress:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "3.0.8"
        },
        {
            "last_affected": "3.0.8"
        },
        {
            "introduced": "3.0.9"
        },
        {
            "last_affected": "3.0.9"
        },
        {
            "introduced": "3.1.0"
        },
        {
            "last_affected": "3.1.0"
        },
        {
            "introduced": "3.1.1"
        },
        {
            "last_affected": "3.1.1"
        },
        {
            "introduced": "3.1.2"
        },
        {
            "last_affected": "3.1.2"
        },
        {
            "fixed": "3.1.3"
        }
    ]
}

Affected versions

3.*
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
v3.*
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10519.json"