What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chetan Khandla WooCommerce Order Search woocommerce-order-searching allows Reflected XSS.This issue affects WooCommerce Order Search: from n/a through <= 1.1.0.
Explanation of Vulnerability in Simple Terms
02Summary
WooCommerce Order Search versions 1.1.0 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a victim's browser when they visit a crafted link. The vulnerability affects the order search functionality and can compromise user sessions or steal sensitive data. Site owners should update to a version newer than 1.1.0.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in a victim's browser when they click a crafted link.
Potential impact on your site
04Site Impact
Users' sessions or credentials could be compromised if they interact with a malicious link targeting your site.
Conditions required to exploit
05Prerequisites
Victim must click a malicious link or visit an attacker-controlled page that triggers the vulnerability.
Key dates
06Disclosure timeline
January 22, 2025
CVE published
April 28, 2026
Record updated