cve/2024/CVE-2024-22288.md
2025-09-29 21:09:30 +02:00

994 B

CVE-2024-22288

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.4.0.

POC

Reference

No PoCs from references.

Github