CVE-2022-2537: WooCommerce PDF Invoices & Packing Slips < 3.0.1 - Reflected Cross-Site Scripting
Published Aug 29, 2022
·Updated
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.
Affected Software
1 affected component
Wpovernight Woocommerce Pdf Invoices\& Packing Slips Wordpress>=2.14.0<3.0.1
Event History
Aug 29, 2022
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2537?
The severity of CVE-2022-2537 is rated as medium with a CVSS score of 6.1.
2
How to fix CVE-2022-2537?
To fix CVE-2022-2537, update the WooCommerce PDF Invoices & Packing Slips WordPress plugin to version 3.0.1 or newer.
3
What is the CWE associated with CVE-2022-2537?
The CWE associated with CVE-2022-2537 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).