Input validation vulnerability in WooCommerce Customers Manager 26.7

The Woocommerce Customers Manager plugin for WordPress has a security vulnerability that can be exploited. In versions before 26.6, if a user clicks on a link which has been crafted by an unauthenticated attacker, it may cause malicious web scripts to be executed. This is because the plugin does not check the inputs of certain parameters (‘wccm_customers_ids’ and ‘wccm_customers_emails’) properly and does not output them in a secure manner.

Detected in:

WooCommerce Customers Manager fixed vulnerable versions: >= * <= 26.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.