Vulnerabilities > Booster > Booster FOR Woocommerce > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-04 | CVE-2023-48747 | Unspecified vulnerability in Booster for Woocommerce Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster for WooCommerce: from n/a through 7.1.2. | 8.8 |
2024-05-02 | CVE-2024-3957 | Incorrect Authorization vulnerability in Booster for Woocommerce The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. | 7.3 |
2023-01-23 | CVE-2022-4017 | Unspecified vulnerability in Booster for Woocommerce The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, Booster Elite for WooCommerce WordPress plugin before 6.0.1 have either flawed CSRF checks or are missing them completely in numerous places, allowing attackers to make logged in users perform unwanted actions via CSRF attacks | 8.8 |
2022-11-21 | CVE-2022-3763 | Unspecified vulnerability in Booster for Woocommerce The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not have CSRF check in place when deleting files uploaded at the checkout, allowing attackers to make a logged in shop manager or admin delete them via a CSRF attack | 8.1 |