PT-2024-11923 · WordPress · Print Invoice & Delivery Notes

Dc11

·

Published

2024-01-16

·

Updated

2024-01-22

·

CVE-2023-0479

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Print Invoice & Delivery Notes for WooCommerce WordPress plugin versions prior to 4.7.2
Description The issue is caused by a reflected XSS vulnerability, which occurs when a GET value is echoed in an admin note within the WooCommerce orders page. This can be exploited by users with the edit others shop orders capability, given that WooCommerce must be installed and active. The vulnerability is a result of a urldecode() function being used after cleanup with esc url raw(), allowing double encoding.
Recommendations For versions prior to 4.7.2, update to version 4.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the WooCommerce orders page for users with the edit others shop orders capability until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-0479

Affected Products

Print Invoice & Delivery Notes