Vulnerabilities > Tychesoftwares > Product Delivery Date FOR Woocommerce > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-04 CVE-2024-9345 Cross-site Scripting vulnerability in Tychesoftwares Product Delivery Date for Woocommerce
The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.3.
network
low complexity
tychesoftwares CWE-79
6.1