CVE-2024-7846: Yithemes Yith Woocommerce AJAX Search

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.

Affected products

  • Yithemes Yith Woocommerce AJAX Search: before 2.7.1 (fixed in 2.7.1)

Published 2024-09-23. Last modified 2026-06-17.