Title: CSS Vulnerability
Last modified: March 15, 2023

---

# CSS Vulnerability

 *  [TomCobbley](https://wordpress.org/support/users/tomcobbley/)
 * (@tomcobbley)
 * [3 years, 5 months ago](https://wordpress.org/support/topic/css-vulnerability-2/)
 * Hello plugin authors, 
   Are you aware of the vulnerability that has been flagged
   for this plugin?[Print Invoice & Delivery Notes for WooCommerce <= 4.7.1 – Reflected Cross-Site Scripting (wordfence.com)](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-delivery-notes/print-invoice-delivery-notes-for-woocommerce-471-reflected-cross-site-scripting)
   Are you working on a fix?

Viewing 10 replies - 1 through 10 (of 10 total)

 *  [bcolflesh](https://wordpress.org/support/users/bcolflesh/)
 * (@bcolflesh)
 * [3 years, 5 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16566517)
 * Wordfence tagged everyone using this plugin and said to deactivate and delete
   ASAP yesterday – can we get an update?
 *  [anotherdave](https://wordpress.org/support/users/anotherdave/)
 * (@anotherdave)
 * [3 years, 5 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16566786)
 * iThemes Security reports 4.7.2 as vulnerable to CSRF as well.
 *  [stoelwinder](https://wordpress.org/support/users/stoelwinder/)
 * (@stoelwinder)
 * [3 years, 5 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16568085)
 * As per the vulnerability report, this issue seems to be fixed for version 4.7.2
   onwards. If you’re using 4.7.1 or lower, please update to 4.7.2 soonest to avoid
   your site being vulnerable to the CSS issue.
 *  [wzshop](https://wordpress.org/support/users/wzshop/)
 * (@wzshop)
 * [3 years, 5 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16568730)
 * Also after updating, wordfence still flag it as a vulnerability issue. When will
   it get fixed?
 *  Thread Starter [TomCobbley](https://wordpress.org/support/users/tomcobbley/)
 * (@tomcobbley)
 * [3 years, 4 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16569931)
 * 4.7.2 is being reported as vulnerable too.
 *  [Moksha Shah](https://wordpress.org/support/users/mokshasharmila13/)
 * (@mokshasharmila13)
 * [3 years, 4 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16570139)
 * Hi [@tomcobbley](https://wordpress.org/support/users/tomcobbley/) ,@wzshop ,@
   stoelwinder ,@anotherdave ,@bcolflesh
 * Sorry for the inconvenience.
   Yes, We are looking into this & will get back to
   you soon with a solution.
 * Regards,
   Moksha.
 *  [Moksha Shah](https://wordpress.org/support/users/mokshasharmila13/)
 * (@mokshasharmila13)
 * [3 years, 4 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16579631)
 * Hi [@tomcobbley](https://wordpress.org/support/users/tomcobbley/), [@wzshop](https://wordpress.org/support/users/wzshop/),
   [@stoelwinder](https://wordpress.org/support/users/stoelwinder/), [@anotherdave](https://wordpress.org/support/users/anotherdave/),
   [@bcolflesh](https://wordpress.org/support/users/bcolflesh/)
 * I apologize for the inconvenience you have faced due to an issue with our plugin.
   We have released v4.7.3 which has the patch for the Cross-Site Request Forgery
   vulnerability issue. Kindly update the plugin and let us know if that resolved
   the issue for you or not.
 * Regards,Moksha.
 *  [anotherdave](https://wordpress.org/support/users/anotherdave/)
 * (@anotherdave)
 * [3 years, 4 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16580297)
 * [@mokshasharmila13](https://wordpress.org/support/users/mokshasharmila13/) After
   updating to 4.7.3 the iThemes Security scan reports back clean, all good. Thank
   you for the update!
 *  [Moksha Shah](https://wordpress.org/support/users/mokshasharmila13/)
 * (@mokshasharmila13)
 * [3 years, 4 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16582919)
 * Hi [@anotherdave](https://wordpress.org/support/users/anotherdave/)
 * Good to know that your problem is resolved.
 * It would be great if you can give a review for the **plugin & the support** on
   [https://wordpress.org/support/plugin/woocommerce-delivery-notes/reviews/#new-post](https://wordpress.org/support/plugin/woocommerce-delivery-notes/reviews/#new-post).
   That would be very helpful.
 * Regards,Moksha.
 *  [anotherdave](https://wordpress.org/support/users/anotherdave/)
 * (@anotherdave)
 * [3 years, 4 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16592742)
 * I couldn’t review the plugin since I don’t use it (a client of mine does) but
   I rated your support 🙂
 * 4.7.3 definitely resolved the issue.

Viewing 10 replies - 1 through 10 (of 10 total)

The topic ‘CSS Vulnerability’ is closed to new replies.

 * ![](https://ps.w.org/woocommerce-delivery-notes/assets/icon-256x256.jpg?rev=2829362)
 * [Print Invoice & Delivery Notes for WooCommerce](https://wordpress.org/plugins/woocommerce-delivery-notes/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/woocommerce-delivery-notes/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/woocommerce-delivery-notes/)
 * [Active Topics](https://wordpress.org/support/plugin/woocommerce-delivery-notes/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/woocommerce-delivery-notes/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/woocommerce-delivery-notes/reviews/)

 * 13 replies
 * 6 participants
 * Last reply from: [anotherdave](https://wordpress.org/support/users/anotherdave/)
 * Last activity: [3 years, 4 months ago](https://wordpress.org/support/topic/css-vulnerability-2/#post-16592742)
 * Status: not resolved