CVE-2024-11779

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocarousel_products_carousel' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>WIP WooCarousel Lite allows you to create a product slider carousel for your WooCommerce website.</p> <p>You can get the premium version, from the following link:</p> <p><a href="https://www.themeinprogress.com/wip-woocarousel-woocommerce-slider-carousel" rel="nofollow ugc">https://www.themeinprogress.com/wip-woocarousel-woocommerce-slider-carousel/</a></p> <p>Install our WIP WooCarousel Lite, to show a carousel with your WooCommerce products.<br /> Live demo: <a href="http://demo.themeinprogress.com/woocarousel/free-version" rel="nofollow ugc">http://demo.themeinprogress.com/woocarousel/free-version/</a></p> <h4>Installation</h4> <p>Once you have installed the plugin, you just need to activate the plugin in order to enable it.</p> <h4>Configuration</h4> <p>WIP WooCarousel Lite will add a new admin page, where you can manage the plugin.</p> <p>You need to insert the shortcode [wip_woocarousel_products_carousel] or use the shortcode generator from the WordPress editor:</p> <p>Below the shortcode configuration.</p> <p>product_items: Add -1 to display all products or insert the number of products to display<br /> product_bestseller: Set this option ON, to display the best seller products for first<br /> product_columns: Set the number of colums for this carousel.<br /> product_rating: Set this option ON, to display the product rating<br /> product_dots: Set this option ON, to display carousel dots</p> <p>[wip_woocarousel_products_carousel product_items=”-1″ product_bestseller=”off|on” product_columns=”1|2|3|4|5…” product_rating=”off|on” product_dots=”off|on”]</p> <h3>Translators</h3> <h4>Available Languages</h4> <ul> <li>English (Default)</li> <li>Italiano</li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
39.9K