CVE-2021-24169
medium · 6.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.
6.1
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2021-04-05
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| algolplus | advanced_order_export_for_woocommerce | < 3.1.8 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/164263/WordPress-Advanced-Order-Export-For-WooCommerce-3.1.7-Cross-Site-Scripting.html
- https://wpscan.com/vulnerability/09681a6c-57b8-4448-982a-fe8d28c87fc3
- http://packetstormsecurity.com/files/164263/WordPress-Advanced-Order-Export-For-WooCommerce-3.1.7-Cross-Site-Scripting.html
- https://wpscan.com/vulnerability/09681a6c-57b8-4448-982a-fe8d28c87fc3
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-24169