Medium severity6.1NVD Advisory· Published Nov 19, 2021· Updated Jun 17, 2026
CVE-2021-42363
CVE-2021-42363
Description
The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.6.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:preview_e-mails_for_woocommerce_project:preview_e-mails_for_woocommerce:*:*:*:*:*:wordpress:*:*Range: <=1.6.8
- Range: <=1.6.8
Patches
Vulnerability mechanics
References
3- plugins.trac.wordpress.org/changeset/2625941/woo-preview-emails/trunk/views/form.phpnvdPatchThird Party Advisory
- www.wordfence.com/blog/2021/11/woocommerce-extension-reflected-xss-vulnerability/nvdExploitThird Party Advisory
- www.wordfence.com/vulnerability-advisories/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.