NikanWP WooCommerce Reporting Stored Cross-Site Scripting Vulnerability via Cross-Site Request Forgery
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability in the NikanWP WooCommerce Reporting plugin, specifically in the wc-reports-lite version 1.0.0, allows for Stored Cross-Site Scripting (XSS) attacks. This vulnerability arises from the plugin's insufficient validation of user input, which can be exploited to inject malicious scripts that are then stored and executed.
Impact
Exploitation of this vulnerability allows for Stored Cross-Site Scripting, where injected scripts are executed in the context of the user.
Added: Oct 27, 2025, 2:29 AM
Updated: Oct 27, 2025, 2:29 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.4exploitability
6.4remediation
0.0relevance
0.8threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
