VYPR

Yith Woocommerce Ajax Search

by Yithemes

CVEs (3)

  • CVE-2024-4455HigMay 24, 2024
    risk 0.40cvss 7.2epss 0.01

    The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2024-7846MedSep 23, 2024
    risk 0.35cvss 5.4epss 0.00

    YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.

  • CVE-2019-16251MedOct 31, 2019
    risk 0.28cvss 4.3epss 0.01

    plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.