Vulnerability Details CVE-2024-49288
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VillaTheme Email Template Customizer for WooCommerce allows Stored XSS.This issue affects Email Template Customizer for WooCommerce: from n/a through 1.2.5.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.3%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2024-49288
-
cpe:2.3:a:villatheme:woocommerce_email_template_customizer:-
-
cpe:2.3:a:villatheme:woocommerce_email_template_customizer:1.2.5