S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24991 Scanner

CVE-2021-24991 scanner - Cross-Site Scripting (XSS) vulnerability in WooCommerce PDF Invoices & Packing Slips plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24991
4.8
CVSS

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WooCommerce PDF Invoices & Packing Slips
AFFECTED< 2.10.5SAFE ✓≥ 2.10.5
Updated Aug 21, 2026View on NVD →
Detail

The WooCommerce PDF Invoices & Packing Slips plugin for Wordpress is a popular tool used by e-commerce businesses to generate invoices and packing slips for their customers. This plugin saves store owners time and effort by automating the process of generating invoices and packing slips, which previously had to be done manually. This plugin has been widely used by many WordPress users, making it an attractive target for cybercriminals.

The CVE-2021-24991 vulnerability detected in this product is a Reflected Cross-Site Scripting vulnerability. This means that the plugin does not properly escape the input data before returning it back to the user, allowing attackers to inject malicious code into the administrative dashboard. An attacker can exploit this vulnerability by tricking the administrator into clicking on a link containing the malicious code. Once clicked, the attacker can steal sensitive information such as user credentials, customer information and payment details.

When exploited, this vulnerability can lead to a potential compromise of the entire WordPress installation and the loss of sensitive data. The attacker can also use the compromised website to further propagate the attack, carry out phishing attacks, or distribute malware to other users. The impact of this vulnerability depends on the level of access an attacker can gain through exploitation.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The pro version allows users to scan their websites for vulnerabilities, generate detailed reports and receive recommendations to protect against such vulnerabilities. By using S4E, businesses can enhance the security of their digital assets and safeguard against potential cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, including:

  • Regularly update the WooCommerce PDF Invoices & Packing Slips plugin to the latest version
  • Keep WordPress, themes, and plugins up to date
  • Use security plugins on your WordPress site to help detect and protect against vulnerabilities
  • Be cautious of links coming from unknown or suspicious sources
  • Teach your employees and site users about digital security best practices

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.