CVE-2021-24991
03.01.2022, 13:15
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard
Vendor | Product | Version |
---|---|---|
wpovernight | woocommerce_pdf_invoices\&_packing_slips | 𝑥 < 2.10.5 |
𝑥
= Vulnerable software versions