cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-12435,https://securityvulnerability.io/vulnerability/CVE-2024-12435,Reflected Cross-Site Scripting in Compare Products for WooCommerce Plugin,"The Compare Products for WooCommerce plugin for WordPress is vulnerable to a Reflected Cross-Site Scripting (XSS) flaw through the 's_feature' parameter. This vulnerability arises from inadequate input sanitization and output escaping in all versions up to 3.2.1. By exploiting this weakness, unauthenticated attackers could inject malicious scripts into web pages. These scripts could execute within the user's browser if the attacker successfully persuades them to perform actions such as clicking on a specially crafted link, potentially compromising user data and site integrity.",Wordpress,Compare Products For WooCommerce,6.1,MEDIUM,0.0005200000014156103,false,,false,false,false,false,false,false,2025-01-07T04:22:23.499Z,0 CVE-2024-12313,https://securityvulnerability.io/vulnerability/CVE-2024-12313,PHP Object Injection Vulnerability in Compare Products for WooCommerce Plugin,"The Compare Products for WooCommerce plugin for WordPress is susceptible to PHP Object Injection due to unsafe deserialization of untrusted input from the 'woo_compare_list' cookie across all versions up to and including 3.2.1. This vulnerability enables unauthenticated attackers to inject arbitrary PHP objects. While the vulnerable software lacks a known Point of Possibility (POP) chain, the risk escalates if additional plugins or themes are installed on the target system, potentially allowing attackers to execute arbitrary code, delete files, or access sensitive data.",Wordpress,Compare Products For WooCommerce,8.1,HIGH,0.0006300000241026282,false,,false,false,false,false,false,false,2025-01-07T04:22:01.100Z,0