HIGH🇵🇱 Wersja polska

CVE-2024-13708

CVSS 7.2v3.1pub. 2025-04-04upd. 2025-04-09

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
  • Booster For Woocommerce

    APP
    Booster
    4.0.1 – 7.2.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSSAuth Bypass
CWE
References

Related vulnerabilities

CVE-2021-34646CRITICAL9.8PL ✓same product

Authentication bypass w pluginie Booster for WooCommerce (WordPress)

CVE-2025-64196HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl...

CVE-2024-13342HIGH8.1same product

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t...

CVE-2025-39446HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl...

CVE-2024-13744HIGH8.1same product

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t...