CVE-2018-11485

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
01/06/2018
Last modified:
02/07/2018

Description

The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:multidots:woocommerce_quick_reports:*:*:*:*:*:wordpress:*:* 1.0.6 (including)