Input validation vulnerability in WooCommerce Report 1.4.5

The WooCommerce Report plugin for WordPress is at risk for a type of attack called Reflected Cross-Site Scripting. This can happen in any version of the plugin, including the latest one. The issue is caused by not properly cleaning up the information that is entered into the plugin and then displayed on the website. This means that someone who does not have an account on the website can insert harmful code into a page and trick a user into clicking on it.

Detected in:

Advanced Report for WooCommerce fixed vulnerable versions: >= * <= 1.4.5
REPORTiT – Advanced WooCommerce Reporting fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.