The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-06-01T15:00:00
Updated: 2024-08-05T08:10:14.629Z
Reserved: 2018-05-26T00:00:00
Link: CVE-2018-11485
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-01T15:29:00.360
Modified: 2024-11-21T03:43:27.710
Link: CVE-2018-11485
Redhat
No data.