CVE-2022-2537

CVE-2022-2537: WooCommerce PDF Invoices & Packing Slips < 3.0.1 - Reflected Cross-Site Scripting

Vendor Unknown
Product WooCommerce PDF Invoices & Packing Slips
Weakness CWE-79 · XSS
Published August 29, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.

Key dates

02Disclosure timeline

August 29, 2022 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE