Lucene search

K
wpvulndbWpvulndbWPVDB-ID:FB883C9F-D8A4-4414-8407-D005F80815B3
HistoryDec 14, 2021 - 12:00 a.m.

WooCommerce EnvioPack <= 1.2 - Reflected Cross-Site Scripting

2021-12-1400:00:00
wpscan.com
7

0.001 Low

EPSS

Percentile

26.4%

The plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter found in the ~/includes/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

CPENameOperatorVersion
woo-enviopackeq*

0.001 Low

EPSS

Percentile

26.4%

Related for WPVDB-ID:FB883C9F-D8A4-4414-8407-D005F80815B3