Vulnerabilities > Directsoftware > Order Attachments FOR Woocommerce > 2.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-02-28 | CVE-2024-13638 | Information Exposure vulnerability in Directsoftware Order Attachments for Woocommerce The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory. | 7.5 |
2024-10-12 | CVE-2024-9756 | Missing Authorization vulnerability in Directsoftware Order Attachments for Woocommerce The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. | 4.3 |