WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels
cpe:2.3:a:webtoffee:woocommerce_pdf_invoices,_packing_slips,_delivery_notes_and_shipping_labels:*:*:*:*:wordpress:*:*
- <= 4.7.1
A stored cross-site scripting vulnerability has been identified in the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin, affecting versions through 4.7.1. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users view the affected content.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the page.
Users of the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin should update to version 4.7.2 or later to address this vulnerability.