Project Subscriptions
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3843 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Stored XSS. This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.7.1. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Stored XSS. This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.7.1. | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels print-invoices-packing-slip-labels-for-woocommerce allows Stored XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through <= 4.7.1. |
| References | ||
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 11 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webtoffee
Webtoffee woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels |
|
| CPEs | cpe:2.3:a:webtoffee:woocommerce_pdf_invoices\,_packing_slips\,_delivery_notes_and_shipping_labels:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Webtoffee
Webtoffee woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels |
Fri, 24 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jan 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Stored XSS. This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.7.1. | |
| Title | WordPress WooCommerce PDF Invoices plugin <= 4.7.1 - Stored Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-01T15:44:21.741Z
Reserved: 2025-01-23T14:51:41.776Z
Link: CVE-2025-24644
Updated: 2025-01-24T18:46:36.801Z
Status : Modified
Published: 2025-01-24T18:15:38.833
Modified: 2026-04-01T17:17:58.743
Link: CVE-2025-24644
No data.
OpenCVE Enrichment
No data.
EUVD