What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCommerce plugin <= 1.2.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCommerce plugin <= 1.2.3 versions.
Explanation of Vulnerability in Simple Terms
The Return and Warranty Management System for WooCommerce contains a cross-site scripting (XSS) vulnerability in versions up to 1.2.3. An attacker can inject malicious scripts that execute in a victim's browser when they visit a crafted link or page. The vulnerability affects the site's integrity and can expose user data or session tokens. Update to a version newer than 1.2.3 to resolve this issue.
What an attacker can do
Inject malicious scripts that run in visitors' browsers, stealing session tokens or redirecting users to phishing sites.
Potential impact on your site
Visitors' browsers can be compromised; user sessions and data may be exposed or manipulated without their knowledge.
Conditions required to exploit
Victim must click a malicious link or visit an attacker-controlled page that triggers the vulnerability.
Key dates
External resources
Related vulnerabilities