Vulnerabilities > Tychesoftwares > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-41858 Cross-Site Request Forgery (CSRF) vulnerability in Tychesoftwares Order Delivery Date for Woocommerce 1.0/1.1/1.2
Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions.
network
low complexity
tychesoftwares CWE-352
8.8
2023-06-07 CVE-2020-36696 Missing Authorization vulnerability in Tychesoftwares Product Input Fields for Woocommerce
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6.
network
low complexity
tychesoftwares CWE-862
7.5
2023-05-25 CVE-2022-45367 Cross-Site Request Forgery (CSRF) vulnerability in Tychesoftwares Custom Order Numbers for Woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Custom Order Numbers for WooCommerce plugin <= 1.4.0 versions.
network
low complexity
tychesoftwares CWE-352
8.8