Input validation vulnerability in WooCommerce 2.4.9

The WooCommerce plugin for WordPress, up to and including version 2.4.8, is vulnerable to a type of security issue called Cross-Site Scripting. This means that if an attacker with administrator privileges injects malicious code into certain pages, it could be executed when another user visits those pages. This is possible because the plugin does not properly check and sanitize inputs, or escape outputs.

Detected in:

WooCommerce fixed vulnerable versions: >= * < 2.4.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.