Vulnerabilities > Woocommerce
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-05 | CVE-2015-10112 | Unspecified vulnerability in Woocommerce Wooframework Branding A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. | 6.1 |
2023-05-28 | CVE-2023-33316 | Unspecified vulnerability in Woocommerce Automatewoo Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions. | 8.8 |
2023-05-28 | CVE-2023-33319 | Unspecified vulnerability in Woocommerce Automatewoo Unauth. | 6.1 |
2023-05-15 | CVE-2023-2179 | Unspecified vulnerability in Woocommerce Order Status Change Notifier The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example | 6.5 |
2023-04-30 | CVE-2015-10104 | Unspecified vulnerability in Woocommerce Icons for Features 1.0.0 A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. | 6.1 |
2022-07-17 | CVE-2022-2099 | Improper Encoding or Escaping of Output vulnerability in Woocommerce The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles | 4.8 |
2022-03-14 | CVE-2021-24940 | Unspecified vulnerability in Woocommerce Persian-Woocommerce The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue | 6.1 |
2021-12-06 | CVE-2021-24938 | Unspecified vulnerability in Woocommerce Currency Switcher The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue | 6.1 |
2021-07-26 | CVE-2021-32790 | SQL Injection vulnerability in Woocommerce Woocommerce is an open source eCommerce plugin for WordPress. | 4.9 |
2021-05-17 | CVE-2021-24323 | Unspecified vulnerability in Woocommerce When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled | 4.8 |