Unrated severityNVD Advisory· Published Nov 19, 2021· Updated Feb 14, 2025
Preview E-Mails for WooCommerce <= 1.6.8 Reflected Cross-Site Scripting
CVE-2021-42363
Description
The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.6.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=1.6.8+ 1 more
- (no CPE)range: <=1.6.8
- (no CPE)range: 1.6.8
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- plugins.trac.wordpress.org/changeset/2625941/woo-preview-emails/trunk/views/form.phpmitrex_refsource_MISC
- www.wordfence.com/blog/2021/11/woocommerce-extension-reflected-xss-vulnerability/mitrex_refsource_MISC
- www.wordfence.com/vulnerability-advisories/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.