Input validation vulnerability in Pre-Orders for WooCommerce 1.2.13

The Pre-Orders plugin for WooCommerce, used with WordPress websites, has a security flaw that could allow attackers with certain permissions to inject malicious web scripts into pages. This vulnerability affects all versions of the plugin up to version 1.2.13 and is caused by a lack of input sanitization and output escaping on the ‘columns’ attribute. If injected, these scripts will execute automatically when a user visits the affected page.

Detected in:

Pre-Orders for WooCommerce fixed vulnerable versions: >= * <= 1.2.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.