CVE-2017-18506: XSS
Published Aug 12, 2019
·Updated
The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.
Affected Software
1 affected component
Wpovernight Woocommerce Pdf Invoices\& Packing Slips Wordpress<2.0.13
Event History
Aug 12, 2019
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18506?
CVE-2017-18506 is a vulnerability in the woocommerce-pdf-invoices-packing-slips plugin before version 2.0.13 for WordPress that allows XSS via the tab or section variable on settings screens.
2
How severe is CVE-2017-18506?
CVE-2017-18506 has a severity rating of 6.1, classified as medium.
3
How can I fix CVE-2017-18506?
To fix CVE-2017-18506, users should update the woocommerce-pdf-invoices-packing-slips plugin to version 2.0.13 or later.