CVE-2023-0479: Print Invoice & Delivery Notes for WooCommerce < 4.7.2 - Reflected XSS
The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the editothersshoporders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with escurlraw(), allowing double encoding.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0479?
CVE-2023-0479 is classified as a reflected XSS vulnerability.
How do I fix CVE-2023-0479?
To fix CVE-2023-0479, update the Print Invoice & Delivery Notes for WooCommerce plugin to version 4.7.2 or later.
Who is affected by CVE-2023-0479?
CVE-2023-0479 affects users with the edit_others_shop_orders capability in the WooCommerce orders page.
What type of vulnerability is CVE-2023-0479?
CVE-2023-0479 is a reflected cross-site scripting (XSS) vulnerability.
When was CVE-2023-0479 disclosed?
CVE-2023-0479 was disclosed prior to the release of the fixed version 4.7.2 of the plugin.