plugin

Ecpay Logistics For Woocommerce Vulnerabilities

1 known security issue reported for the Ecpay Logistics For Woocommerce WordPress plugin. Most recent disclosed Sep 5, 2019.

1 medium

Running Ecpay Logistics For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

ECPay Logistics for WooCommerce <= 1.2.181030 - Reflected Cross-Site Scripting

medium

The ECPay Logistics for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'CVSStoreName', 'CVSStoreIDparameter', 'CVSTelephone', and 'CVSAddress' parameters in versions up to, and including, 1.2.181030 due to insufficient input sanitization and output escaping. This makes it possi...

CVSS:
6.1
Affected:
up to 1.2.181030
Fixed in:
1.3.1910240
Disclosed:
Sep 5, 2019

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database