Stored Cross-Site Scripting in WebToffee WooCommerce PDF Invoices Plugin
CVE-2025-24644

4.8MEDIUM

Key Information:

Summary

A vulnerability has been identified in the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin that allows for stored Cross-Site Scripting (XSS). This issue can be exploited by malicious users to inject harmful scripts into web pages viewed by other users. This risk poses significant threats to user data and application integrity, particularly for versions prior to 4.7.1.

Affected Version(s)

WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.7.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

savphill (Patchstack Alliance)
.