Back to Database
Status published
Medium
CVE-2017-18506
The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via...
Vulnerability Description
The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-18506
Credits & Attribution
No credits recorded in the NVD database.
More from wpovernight
View All →CVE-2025-24373
Unrestricted Access to PDF Documents via URL Manipulation in woocommerce-pdf-invoices-packing-slips
Medium
6.3
CVE-2024-3047
PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Server-Side Request Forgery
High
7.2
CVE-2024-3045
PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting
High
7.2
Affected Vendor
wpovernight
View all reports →Affected Software
woocommerce pdf invoices\& packing slips
Vulnerable Versions:
0
Timeline
Official Publish:
August 12th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.