CVE · Medium

CVE-2021-25062 — Trakoo – Orders Tracking for WooCommerce [woo-orders-tracking] < 1.1.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-25062 Trakoo – Orders Tracking for WooCommerce [woo-orders-tracking] < 1.1.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.1.10 1.1.10 2021-12-27

CVE-2021-25062

The Orders Tracking for WooCommerce plugin versions prior to 1.1.10 contain a reflected cross-site scripting vulnerability because the plugin fails to properly sanitize and escape the file_url parameter before displaying it on an administrator page.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.