CVE Database
/

CVE-2023-0479

Back to search

CVE-2023-0479

Published: Jan 16, 2024

Modified: Jun 20, 2025

PUBLISHED

Description

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.

VendorProductVersions

Unknown

Print Invoice & Delivery Notes for WooCommerce

affected
0 - < 4.7.2

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now