CVE · Medium

CVE-2024-8788 — EU/UK VAT Validation Manager for WooCommerce [eu-vat-for-woocommerce] < 2.12.14

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8788 EU/UK VAT Validation Manager for WooCommerce [eu-vat-for-woocommerce] < 2.12.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.12.14 2.12.14 2024-09-27

CVE-2024-8788

The EU/UK VAT Manager for WooCommerce plugin has a security flaw that allows malicious actors to inject unauthorized code onto vulnerable WordPress sites through a specific type of attack, where attackers manipulate URLs to deceive users into executing malicious scripts. This vulnerability affects all versions up to and including 2.12.11 of the plugin, making it possible for unauthenticated individuals to compromise site integrity.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.