Lucene search

K
wpvulndbJack MisiuraWPVDB-ID:DB7B6799-99FD-4376-8DA4-84885D17B387
HistoryMay 04, 2020 - 12:00 a.m.

Advanced Order Export For WooCommerce < 3.1.4 - Authenticated Cross-Site Scripting (XSS)

2020-05-0400:00:00
Jack Misiura
wpscan.com
12

EPSS

0.002

Percentile

61.4%

The Advanced Order Export plugin for WooCommerce versions < 3.1.4 had a reflected XSS vulnerability due to lack of input sanitization on the woe_post_type parameter. This allowed arbitrary HTML and JavaScript injection and execution in the context of the logged in user.

PoC

On a WooCommerce installation with a vulnerable Advanced Order Export plugin (< 3.1.4), issue the following request while logged in as Administrator: https://example.com/wp-admin/admin.php?page=wc-order-export&amp;tab;=export&amp;woe;_post_type="><script>alert(1);#segment=common

EPSS

0.002

Percentile

61.4%

Related for WPVDB-ID:DB7B6799-99FD-4376-8DA4-84885D17B387