CVE-2024-10519

Source
https://cve.org/CVERecord?id=CVE-2024-10519
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10519.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-10519
Published
2024-11-23T10:15:03.600Z
Modified
2026-04-02T09:48:07.090257Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' parameter in versions 3.0.8 to 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Note: Only WordPress installations with versions of PHP <=7.4 are affected by this vulnerability.

References

Affected packages

Git / github.com/wpcodefactory/wish-list-for-woocommerce

Affected ranges

Type
GIT
Repo
https://github.com/wpcodefactory/wish-list-for-woocommerce
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.0.8"
        },
        {
            "fixed": "3.1.3"
        }
    ]
}

Affected versions

v3.*
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10519.json"