Vulnerabilities > Directsoftware > Order Attachments FOR Woocommerce > 2.2.2

DATE CVE VULNERABILITY TITLE RISK
2025-02-28 CVE-2024-13638 Information Exposure vulnerability in Directsoftware Order Attachments for Woocommerce
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory.
network
low complexity
directsoftware CWE-200
7.5
2024-10-12 CVE-2024-9756 Missing Authorization vulnerability in Directsoftware Order Attachments for Woocommerce
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1.
network
low complexity
directsoftware CWE-862
4.3