CVE-2024-22288: WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.4.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.4.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22288?
The severity of CVE-2024-22288 is considered medium due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2024-22288?
To fix CVE-2024-22288, update the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin to version 4.4.2 or later.
Which versions of the plugin are affected by CVE-2024-22288?
CVE-2024-22288 affects versions of the plugin up to and including 4.4.1.
What type of vulnerability is CVE-2024-22288?
CVE-2024-22288 is an improper neutralization of input during web page generation vulnerability, specifically categorized as reflected XSS.
Who is affected by CVE-2024-22288?
Users of the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin prior to version 4.4.2 are affected by CVE-2024-22288.