CVE · Medium

CVE-2024-2456 — Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2456 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.11 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 6.4 < 6.12.11 6.12.11 2024-03-29

CVE-2024-2456

The Ecwid Shopping Cart plugin for WordPress contains a cross-site scripting vulnerability in versions before 6.12.11 that an attacker could exploit to inject harmful scripts into a website, potentially causing redirects, injecting advertisements, or executing arbitrary HTML when visitors access the site. The vulnerability was discovered by Krzysztof Zając and has been patched in version 6.12.11 and later. Users should upgrade to version 6.12.11 or newer to secure their installations.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.