Lucene search

K
cvePatchstackCVE-2023-46076
HistoryOct 26, 2023 - 1:15 p.m.

CVE-2023-46076

2023-10-2613:15:09
CWE-79
Patchstack
web.nvd.nist.gov
24
cve-2023-46076
unauth
reflected xss
rednao
woocommerce
pdf invoice builder
nvd

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

AI Score

6

Confidence

High

EPSS

0.001

Percentile

17.0%

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin <= 1.2.102 versions.

Affected configurations

Nvd
Vulners
Node
rednaowoocommerce_pdf_invoice_builderRange1.2.102wordpress
VendorProductVersionCPE
rednaowoocommerce_pdf_invoice_builder*cpe:2.3:a:rednao:woocommerce_pdf_invoice_builder:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "woo-pdf-invoice-builder",
    "product": "WooCommerce PDF Invoice Builder, Create invoices, packing slips and more",
    "vendor": "RedNao",
    "versions": [
      {
        "lessThanOrEqual": "1.2.102",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

AI Score

6

Confidence

High

EPSS

0.001

Percentile

17.0%