PT-2021-15715 · WordPress · Advanced Order Export For Woocommerce
0Xb9
·
Published
2021-04-05
·
Updated
2024-11-20
·
CVE-2021-24169
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Advanced Order Export For WooCommerce WordPress plugin versions prior to 3.1.8
Description:
The issue affects the Advanced Order Export For WooCommerce WordPress plugin, where the
tab parameter in the Admin Panel is vulnerable to reflected XSS. This allows for potential malicious script injection.Recommendations:
For versions prior to 3.1.8, update to version 3.1.8 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Admin Panel to minimize the risk of exploitation.
Avoid using the
tab parameter in the Admin Panel until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Order Export For Woocommerce