Security Advisory

CVE-2018-11485

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-06-01 15:00:00
Last updated 2024-08-05 08:10:14
Assigner mitre
State PUBLISHED

Description

The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.