Vulnerabilities > Woocommerce

DATE CVE VULNERABILITY TITLE RISK
2023-05-15 CVE-2023-2179 Unspecified vulnerability in Woocommerce Order Status Change Notifier
The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example
network
low complexity
woocommerce
6.5
2023-04-30 CVE-2015-10104 Open Redirect vulnerability in Woocommerce Icons for Features 1.0.0
A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress.
network
low complexity
woocommerce CWE-601
6.1
2022-07-17 CVE-2022-2099 Improper Encoding or Escaping of Output vulnerability in Woocommerce
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
network
low complexity
woocommerce CWE-116
4.8
2022-03-14 CVE-2021-24940 Cross-site Scripting vulnerability in Woocommerce Persian-Woocommerce
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue
network
low complexity
woocommerce CWE-79
6.1
2021-12-06 CVE-2021-24938 Cross-site Scripting vulnerability in Woocommerce Currency Switcher
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue
network
low complexity
woocommerce CWE-79
6.1
2021-07-26 CVE-2021-32790 SQL Injection vulnerability in Woocommerce
Woocommerce is an open source eCommerce plugin for WordPress.
network
low complexity
woocommerce CWE-89
4.9
2021-05-17 CVE-2021-24323 Cross-site Scripting vulnerability in Woocommerce
When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled
network
low complexity
woocommerce CWE-79
4.8
2021-04-05 CVE-2021-24212 Unrestricted Upload of File with Dangerous Type vulnerability in Woocommerce Help Scout
The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.
network
low complexity
woocommerce CWE-434
critical
9.8
2021-04-05 CVE-2021-24171 Unrestricted Upload of File with Dangerous Type vulnerability in Woocommerce Upload Files
The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php.
network
low complexity
woocommerce CWE-434
critical
9.8
2020-12-28 CVE-2020-35627 Unrestricted Upload of File with Dangerous Type vulnerability in Woocommerce Gift Cards 3.0.2
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code.
network
low complexity
woocommerce CWE-434
8.8