4.3
CVSSv2

CVE-2018-11485

Published: 01/06/2018 Updated: 02/07/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and previous versions for WordPress is vulnerable to Stored XSS. It allows an malicious user to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.

Vulnerable Product Search on Vulmon Subscribe to Product

multidots woocommerce quick reports