Vulnerability Description
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpovernight | Woocommerce Pdf Invoices\& Packing Slips | < 2.16.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/87546554-276a-45fe-b2aa-b18bfc55db2dExploitThird Party Advisory
- https://wpscan.com/vulnerability/87546554-276a-45fe-b2aa-b18bfc55db2dExploitThird Party Advisory
FAQ
What is CVE-2022-2092?
CVE-2022-2092 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting a...
How severe is CVE-2022-2092?
CVE-2022-2092 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2092?
Check the references section above for vendor advisories and patch information. Affected products include: Wpovernight Woocommerce Pdf Invoices\& Packing Slips.