CVE-2025-24644: WordPress WooCommerce PDF Invoices plugin <= 4.7.1 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels print-invoices-packing-slip-labels-for-woocommerce allows Stored XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through <= 4.7.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24644?
CVE-2025-24644 is classified as a Stored Cross-Site Scripting (XSS) vulnerability, which can allow an attacker to execute arbitrary JavaScript code in the context of a user's session.
How do I fix CVE-2025-24644?
To fix CVE-2025-24644, update the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin to version 4.7.2 or later.
Which versions of the software are affected by CVE-2025-24644?
CVE-2025-24644 affects versions of WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels up to and including version 4.7.1.
What can an attacker do by exploiting CVE-2025-24644?
An attacker exploiting CVE-2025-24644 can store malicious scripts that execute when viewed by users, potentially compromising their data and sessions.
Is CVE-2025-24644 considered a critical vulnerability?
CVE-2025-24644 is not considered critical but poses a significant risk due to its potential for enabling data theft and session hijacking.