Vulnerabilities > Yikesinc > Custom Product Tabs FOR Woocommerce > 1.5.9

DATE CVE VULNERABILITY TITLE RISK
2025-01-07 CVE-2024-11465 Deserialization of Untrusted Data vulnerability in Yikesinc Custom Product Tabs for Woocommerce
The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input in the 'yikes_woo_products_tabs' post meta parameter.
network
low complexity
yikesinc CWE-502
7.2
2022-11-18 CVE-2022-43463 Cross-site Scripting vulnerability in Yikesinc Custom Product Tabs for Woocommerce
Auth.
network
low complexity
yikesinc CWE-79
4.8
2022-07-21 CVE-2022-28666 Unspecified vulnerability in Yikesinc Custom Product Tabs for Woocommerce
Broken Access Control vulnerability in YIKES Inc.
network
low complexity
yikesinc
5.3