Skip to main content
Vulnerability Database/CVE-2024-12278

CVE-2024-12278: Booster For WooCommerce XSS Vulnerability

CVE-2024-12278 is a stored cross-site scripting vulnerability in Booster for WooCommerce plugin that allows unauthenticated attackers to inject malicious scripts. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2024-12278 Overview

The Booster for WooCommerce plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability [CWE-79] affecting all versions up to and including 7.2.4. The flaw exists in code paths that rely on wp_kses for sanitization, such as comments. Insufficient input sanitization and output escaping allow unauthenticated attackers to inject arbitrary web scripts. Injected payloads execute in the browser of any user who accesses the affected page. The vulnerability was published to the National Vulnerability Database (NVD) on April 1, 2025.

Critical Impact

Unauthenticated attackers can inject persistent JavaScript into WooCommerce storefronts, enabling session theft, credential harvesting, and administrative account takeover through victim interaction.

Affected Products

  • Booster for WooCommerce plugin for WordPress, all versions through 7.2.4
  • WordPress sites running the vulnerable plugin (woocommerce-jetpack)
  • E-commerce deployments relying on wp_kses sanitization paths exposed by the plugin

Discovery Timeline

  • 2025-04-01 - CVE-2024-12278 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-12278

Vulnerability Analysis

The vulnerability resides in the Booster for WooCommerce plugin's handling of user-supplied content processed through WordPress' wp_kses filtering system. The plugin fails to correctly sanitize input or escape output in contexts where wp_kses is typically the last line of defense, such as comment fields. Attackers submit crafted payloads that bypass the sanitization logic and persist in the site's database. When any user, including administrators, renders a page containing the stored payload, the browser executes attacker-controlled JavaScript. Because exploitation requires no authentication, any anonymous visitor can seed persistent scripts across an affected storefront.

Root Cause

The root cause is insufficient input sanitization and output escaping in a helper function within includes/functions/wcj-functions-general.php. The function processed HTML through a path that did not adequately restrict attributes or event handlers permitted by wp_kses, allowing script-carrying markup to survive filtering. The upstream fix is recorded in changeset 3262569.

Attack Vector

Exploitation occurs over the network without authentication and requires only that a victim visit a page containing the injected payload. An attacker submits a malicious payload through any input processed by the vulnerable helper, such as a comment. The payload is stored server-side and rendered on subsequent page loads. When a logged-in administrator views the affected page, the attacker can hijack the session, perform actions in the admin context, or pivot to further compromise.

No verified public proof-of-concept code is available. See the Wordfence Vulnerability Analysis and the vulnerable WordPress WooCommerce Jetpack Code for technical details.

Detection Methods for CVE-2024-12278

Indicators of Compromise

  • Unexpected <script> tags, on* event handlers, or javascript: URIs stored in wp_comments, WooCommerce order notes, or plugin-managed fields.
  • Outbound requests from visitor browsers to unfamiliar domains after loading storefront or product pages.
  • New or modified WordPress administrator accounts appearing shortly after anonymous comment activity.

Detection Strategies

  • Review the wp_comments table and plugin-related metadata for HTML markup that would not normally survive wp_kses sanitization.
  • Deploy a web application firewall (WAF) ruleset that identifies XSS payloads submitted to comment and WooCommerce endpoints.
  • Correlate anonymous POST requests to comment or checkout endpoints with subsequent administrator session activity.

Monitoring Recommendations

  • Enable verbose logging on WordPress and the reverse proxy, capturing full request bodies for comment and plugin endpoints.
  • Alert on modifications to the woocommerce-jetpack plugin directory outside of scheduled maintenance windows.
  • Monitor administrator authentication events for anomalous IPs or user agents following comment submissions from untrusted sources.

How to Mitigate CVE-2024-12278

Immediate Actions Required

  • Update Booster for WooCommerce to a version later than 7.2.4 that includes the fix from changeset 3262569.
  • Audit stored comments, reviews, and plugin-managed content for previously injected payloads and remove malicious entries.
  • Rotate credentials and force re-authentication for administrator accounts that accessed affected pages during the exposure window.

Patch Information

The vendor addressed the flaw in the wcj-functions-general.php helper referenced in WordPress plugin changeset 3262569. Site operators should upgrade to the fixed release published on WordPress.org and confirm the plugin version reported in the admin dashboard reflects the patched build.

Workarounds

  • Temporarily disable the Booster for WooCommerce plugin until the patched version is installed.
  • Disable anonymous comments on WordPress and require authentication for interactive content submission.
  • Deploy a WAF rule that blocks HTML tags and event-handler attributes in requests targeting comment and WooCommerce submission endpoints.
bash
# Example: temporarily deactivate the plugin via WP-CLI while planning the upgrade
wp plugin deactivate woocommerce-jetpack

# Verify installed version, then upgrade after the patched release is available
wp plugin get woocommerce-jetpack --field=version
wp plugin update woocommerce-jetpack

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.