Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2069
Reference (s):
- BID:74885
- URL: http://www.securityfocus.com/bid/74885
- https://wordpress.org/plugins/woocommerce/changelog/
- FULLDISC:20150221 WooCommerce WordPress plugin 2.2.10 Reflected XSS
- URL: http://seclists.org/fulldisclosure/2015/Feb/75

