Lucene search

K
wpvulndbChloe ChamberlandWPVDB-ID:F64EAF2D-B089-41EC-8A26-B19CFB67E435
HistoryNov 17, 2021 - 12:00 a.m.

Preview E-mails for WooCommerce < 2.0.0 - Reflected Cross-Site Scripting

2021-11-1700:00:00
Chloe Chamberland
wpscan.com
12
woocommerce
reflected cross-site scripting
search order parameter

EPSS

0.001

Percentile

37.6%

The plugin is vulnerable to reflected XSS via the search_order parameter found in the ~/views/form.php file.

PoC

EPSS

0.001

Percentile

37.6%

Related for WPVDB-ID:F64EAF2D-B089-41EC-8A26-B19CFB67E435