Vulnerabilities > Storeapps > High

DATE CVE VULNERABILITY TITLE RISK
2024-02-12 CVE-2024-0566 SQL Injection vulnerability in Storeapps Smart Manager
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
network
low complexity
storeapps CWE-89
7.2
2023-07-11 CVE-2023-35091 Unspecified vulnerability in Storeapps Stock Manager for Woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <= 2.10.0 versions.
network
low complexity
storeapps
8.8
2022-08-05 CVE-2022-25649 Unspecified vulnerability in Storeapps Affiliate for Woocommerce
Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.
network
low complexity
storeapps
8.8
2021-07-21 CVE-2021-34619 Cross-Site Request Forgery (CSRF) vulnerability in Storeapps Stock Manager for Woocommerce
The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.
network
low complexity
storeapps CWE-352
8.8