First published: Mon Jan 03 2022(Updated: )
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Overnight WooCommerce PDF Invoices & Packing Slips | <2.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24991 has a medium severity rating due to its potential for reflected Cross-Site Scripting in the admin dashboard.
To fix CVE-2021-24991, update the WooCommerce PDF Invoices & Packing Slips plugin to version 2.10.5 or later.
CVE-2021-24991 affects the WooCommerce PDF Invoices & Packing Slips plugin versions prior to 2.10.5 on WordPress.
CVE-2021-24991 is a reflected Cross-Site Scripting vulnerability.
Yes, an attacker can exploit CVE-2021-24991 to execute scripts in the context of the admin user's session.