Vulnerabilities > Booster > Booster FOR Woocommerce > High

DATE CVE VULNERABILITY TITLE RISK
2023-01-23 CVE-2022-4017 Unspecified vulnerability in Booster for Woocommerce
The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, Booster Elite for WooCommerce WordPress plugin before 6.0.1 have either flawed CSRF checks or are missing them completely in numerous places, allowing attackers to make logged in users perform unwanted actions via CSRF attacks
network
low complexity
booster
8.8
2022-11-21 CVE-2022-3763 Unspecified vulnerability in Booster for Woocommerce
The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not have CSRF check in place when deleting files uploaded at the checkout, allowing attackers to make a logged in shop manager or admin delete them via a CSRF attack
network
low complexity
booster
8.1
2021-08-30 CVE-2021-34646 Use of Insufficiently Random Values vulnerability in Booster for Woocommerce
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file.
network
low complexity
booster CWE-330
7.5