Vulnerabilities > Tychesoftwares > Product Input Fields FOR Woocommerce

DATE CVE VULNERABILITY TITLE RISK
2025-03-08 CVE-2024-13359 Unrestricted Upload of File with Dangerous Type vulnerability in Tychesoftwares Product Input Fields for Woocommerce
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0.
network
low complexity
tychesoftwares CWE-434
critical
9.8
2023-06-07 CVE-2020-36696 Missing Authorization vulnerability in Tychesoftwares Product Input Fields for Woocommerce
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6.
network
low complexity
tychesoftwares CWE-862
7.5