CVE Database /
CVE-2024-2456
CVE · Medium
CVE-2024-2456 — Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.11
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-2456
|
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.11 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
Medium
6.4
|
< 6.12.11
|
6.12.11 |
2024-03-29 |
—
|
CVE-2024-2456
The Ecwid Shopping Cart plugin for WordPress contains a cross-site scripting vulnerability in versions before 6.12.11 that an attacker could exploit to inject harmful scripts into a website, potentially causing redirects, injecting advertisements, or executing arbitrary HTML when visitors access the site. The vulnerability was discovered by Krzysztof Zając and has been patched in version 6.12.11 and later. Users should upgrade to version 6.12.11 or newer to secure their installations.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings