CVE-2021-24991: WooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site Scripting
Published Jan 3, 2022
·Updated
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard
Affected Software
1 affected component
Wpovernight Woocommerce Pdf Invoices\& Packing Slips Wordpress<2.10.5
Event History
Jan 3, 2022
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24991?
CVE-2021-24991 has a medium severity rating due to its potential for reflected Cross-Site Scripting in the admin dashboard.
2
How do I fix CVE-2021-24991?
To fix CVE-2021-24991, update the WooCommerce PDF Invoices & Packing Slips plugin to version 2.10.5 or later.
3
What systems are affected by CVE-2021-24991?
CVE-2021-24991 affects the WooCommerce PDF Invoices & Packing Slips plugin versions prior to 2.10.5 on WordPress.
4
What type of vulnerability is CVE-2021-24991?
CVE-2021-24991 is a reflected Cross-Site Scripting vulnerability.
5
Can CVE-2021-24991 be exploited by an attacker?
Yes, an attacker can exploit CVE-2021-24991 to execute scripts in the context of the admin user's session.