Preview E-Mails for WooCommerce <= 1.6.8 Reflected Cross-Site Scripting
CVE-2021-42363
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 November 2021
What is CVE-2021-42363?
The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.6.8.
Affected Version(s)
Preview E-Mails for WooCommerce 1.6.8