Stored Cross-Site Scripting in WebToffee WooCommerce PDF Invoices Plugin
CVE-2025-24644
4.8MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 24 January 2025
Summary
A vulnerability has been identified in the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin that allows for stored Cross-Site Scripting (XSS). This issue can be exploited by malicious users to inject harmful scripts into web pages viewed by other users. This risk poses significant threats to user data and application integrity, particularly for versions prior to 4.7.1.
Affected Version(s)
WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.7.1
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
savphill (Patchstack Alliance)