CVE · Low

CVE-2024-35777 — WooCommerce [woocommerce] < 9.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-35777 WooCommerce [woocommerce] < 9.0.0 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Low 3.5 < 9.0.0 9.0.0 2024-06-27

CVE-2024-35777

WooCommerce for WordPress contains a content injection vulnerability affecting versions through 8.9.2 that arises from insufficient input validation and content restrictions. Attackers with Shop Manager privileges or higher can exploit this flaw to inject malicious content into the application. The vulnerability requires authenticated access at an elevated privilege level to be exploited.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.