CVE Database /
CVE-2017-18506
CVE · Medium
CVE-2017-18506 — PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-18506
|
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.0.13
|
2.0.13 |
2017-10-02 |
—
|
CVE-2017-18506
The woocommerce-pdf-invoices-packing-slips plugin for WordPress before version 2.0.13 contains a cross-site scripting vulnerability where user input from the tab and section parameters on the plugin's settings pages is not properly sanitized, allowing attackers to inject malicious scripts that execute in the context of administrative users' browsers.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings