The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Tue, 11 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpovernight
Wpovernight woocommerce Pdf Invoices\& Packing Slips
Weaknesses CWE-79
CPEs cpe:2.3:a:wpovernight:woocommerce_pdf_invoices\&_packing_slips:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpovernight
Wpovernight woocommerce Pdf Invoices\& Packing Slips

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T19:32:42.660Z

Reserved: 2024-03-28T15:45:47.824Z

Link: CVE-2024-3045

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.660Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-02T17:15:21.997

Modified: 2025-02-11T17:02:05.947

Link: CVE-2024-3045

cve-icon Redhat

No data.