SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-24169

The tab parameter in the Admin Panel is vulnerable to reflected XSS.

MEDIUM 6.1EPSS 10.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 10.3%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.

Description

This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
10.35% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
algolplus/advanced order export for woocommerce
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.