CVE-2018-11485
Advance Search for WooCommerce < 1.1 - Cross-Site Scripting
Severity Score
6.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
El plugin WooCommerce Quick Reports en versiones 1.0.6 y anteriores de MULTIDOTS para WordPress es vulnerable a Cross-Site Scripting (XSS) persistente. Permite que un atacante inyecte código JavaScript en la página de administrador WooCommerce -> Orders. El ataque es posible modificando la cookie "referral_site" para que tenga una carga útil XSS y haciendo un pedido.
*Credits:
ThreatPress
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-05-26 CVE Reserved
- 2018-05-30 CVE Published
- 2024-04-10 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
http://labs.threatpress.com/stored-cross-site-scripting-xss-in-woocommerce-quick-reports-plugin | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Multidots Search vendor "Multidots" | Woocommerce Quick Reports Search vendor "Multidots" for product "Woocommerce Quick Reports" | <= 1.0.6 Search vendor "Multidots" for product "Woocommerce Quick Reports" and version " <= 1.0.6" | wordpress |
Affected
|