VendorsMultidotswoocommerce_quick_reportsall versions
Vulnerabilities

Multidots Woocommerce Quick Reports

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2018-11485
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
Published 2018-06-01 · Modified
6.1EPSS 0.008