CVE-2024-11779
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocarousel_products_carousel' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<p>WIP WooCarousel Lite allows you to create a product slider carousel for your WooCommerce website.</p>
<p>You can get the premium version, from the following link:</p>
<p><a href="https://www.themeinprogress.com/wip-woocarousel-woocommerce-slider-carousel" rel="nofollow ugc">https://www.themeinprogress.com/wip-woocarousel-woocommerce-slider-carousel/</a></p>
<p>Install our WIP WooCarousel Lite, to show a carousel with your WooCommerce products.<br />
Live demo: <a href="http://demo.themeinprogress.com/woocarousel/free-version" rel="nofollow ugc">http://demo.themeinprogress.com/woocarousel/free-version/</a></p>
<h4>Installation</h4>
<p>Once you have installed the plugin, you just need to activate the plugin in order to enable it.</p>
<h4>Configuration</h4>
<p>WIP WooCarousel Lite will add a new admin page, where you can manage the plugin.</p>
<p>You need to insert the shortcode [wip_woocarousel_products_carousel] or use the shortcode generator from the WordPress editor:</p>
<p>Below the shortcode configuration.</p>
<p>product_items: Add -1 to display all products or insert the number of products to display<br />
product_bestseller: Set this option ON, to display the best seller products for first<br />
product_columns: Set the number of colums for this carousel.<br />
product_rating: Set this option ON, to display the product rating<br />
product_dots: Set this option ON, to display carousel dots</p>
<p>[wip_woocarousel_products_carousel product_items=”-1″ product_bestseller=”off|on” product_columns=”1|2|3|4|5…” product_rating=”off|on” product_dots=”off|on”]</p>
<h3>Translators</h3>
<h4>Available Languages</h4>
<ul>
<li>English (Default)</li>
<li>Italiano</li>
</ul>