CVE-2018-11485: XSS
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referralsite" cookie to have an XSS payload, and placing an order.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11485?
The severity of CVE-2018-11485 is medium with a CVSS score of 6.1.
How does CVE-2018-11485 affect the MULTIDOTS WooCommerce Quick Reports plugin?
CVE-2018-11485 allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page through the MULTIDOTS WooCommerce Quick Reports plugin.
How can an attacker exploit CVE-2018-11485?
An attacker can exploit CVE-2018-11485 by modifying the "referral_site" cookie to have an XSS payload.
Is there a fix available for CVE-2018-11485?
Yes, it is recommended to update the MULTIDOTS WooCommerce Quick Reports plugin to version 1.0.7 or later to fix CVE-2018-11485.
Where can I find more information about CVE-2018-11485?
You can find more information about CVE-2018-11485 at the following link: http://labs.threatpress.com/stored-cross-site-scripting-xss-in-woocommerce-quick-reports-plugin/