The Wordpress plugin WooCommerce PDF Invoices & Packing Slips before 2.10.5 does not escape the tab and section parameters before reflecting it an attribute, leading to a reflected cross-site scripting in the admin dashboard.
id: CVE-2021-24991
info:
name: WooCommerce PDF Invoices & Packing Slips WordPress Plugin < 2.10.5
...