CVE-2024-7846: Yithemes Yith Woocommerce AJAX Search
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.
Affected products
- Yithemes Yith Woocommerce AJAX Search: before 2.7.1 (fixed in 2.7.1)
Published 2024-09-23. Last modified 2026-06-17.