CVE-2021-24991
WooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site Scripting
Record summary
CVE-2021-24991 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.
Description
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WooCommerce PDF Invoices & Packing Slips | CVE List | 2.10.5 to < 2.10.5 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWooCommerce PDF Invoices & Packing Slips WordPress Plugin < 2.10.5 - Cross-Site ScriptingCVSS 4.8
The Wordpress plugin WooCommerce PDF Invoices & Packing Slips before 2.10.5 does not escape the tab and section parameters before reflecting it an attribute, leading to a reflected cross-site scripting in the admin dashboard.
Impact
An attacker can exploit this vulnerability to inject malicious scripts into web pages viewed by users, leading to potential theft of sensitive information or unauthorized actions.
Remediation
Update to the latest version of the WooCommerce PDF Invoices & Packing Slips WordPress Plugin (2.10.5 or higher) to mitigate the vulnerability.
Source: ProjectDiscovery