Vulnerabilities > Woocommerce > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-06-05 CVE-2015-10115 Unspecified vulnerability in Woocommerce Sidebar Manager to Woosidebars Converter
A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress.
network
low complexity
woocommerce
6.1
2023-06-05 CVE-2015-10113 Unspecified vulnerability in Woocommerce Wooframework Tweaks 1.0.0/1.0.1
A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress.
network
low complexity
woocommerce
6.1
2023-06-05 CVE-2015-10114 Unspecified vulnerability in Woocommerce Woosidebars
A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress.
network
low complexity
woocommerce
6.1
2023-06-05 CVE-2015-10112 Unspecified vulnerability in Woocommerce Wooframework Branding
A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress.
network
low complexity
woocommerce
6.1
2023-05-28 CVE-2023-33319 Unspecified vulnerability in Woocommerce Automatewoo
Unauth.
network
low complexity
woocommerce
6.1
2023-05-15 CVE-2023-2179 Unspecified vulnerability in Woocommerce Order Status Change Notifier
The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example
network
low complexity
woocommerce
6.5
2023-04-30 CVE-2015-10104 Unspecified vulnerability in Woocommerce Icons for Features 1.0.0
A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress.
network
low complexity
woocommerce
6.1
2022-07-17 CVE-2022-2099 Improper Encoding or Escaping of Output vulnerability in Woocommerce
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
network
low complexity
woocommerce CWE-116
4.8
2022-03-14 CVE-2021-24940 Unspecified vulnerability in Woocommerce Persian-Woocommerce
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue
network
low complexity
woocommerce
6.1
2021-12-06 CVE-2021-24938 Unspecified vulnerability in Woocommerce Currency Switcher
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue
network
low complexity
woocommerce
6.1