CVE-2018-11485
01.06.2018, 15:29
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
Vendor | Product | Version |
---|---|---|
multidots | woocommerce_quick_reports | 𝑥 ≤ 1.0.6 |
𝑥
= Vulnerable software versions