QID 150566
Date Published: 2022-09-12
QID 150566: WordPress WooCommerce PDF Invoices and Packing Slips Plugin: Reflected Cross-Site Scripting Vulnerability (CVE-2022-2537)
WooCommerce PDF Invoice and Packing Slips is a WooCommerce extension plugin that automatically adds a PDF invoice to the order confirmation emails sent out to your customers.
The plugin does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard.
Affected versions:
WooCommerce PDF Invoice and Packing Slips from 2.14.0 to 3.0.1
QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a plugin running on the target application.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive browser-based information.
CVEs related to QID 150566
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WPScan |
|