WordPress Plugin Vulnerabilities

ECPay Logistics for WooCommerce < 1.3.1910240 - Unauthenticated Reflected XSS

Description

The CVSStoreName, CVSAddress, CVSTelephone and CVSStoreID from the getChangeResponse.php are affected by Reflected XSS issues.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Ricardo Sanchez
Verified
Yes

Timeline

Publicly Published
2019-09-05 (about 6 years ago)
Added
2019-09-06 (about 6 years ago)
Last Updated
2021-07-17 (about 4 years ago)

Other