Show filters
69 Total Results
Displaying 11-20 of 69
Sort by:
Attacker Value
Unknown

CVE-2024-8499

Disclosure Date: October 04, 2024 (last updated November 09, 2024)
The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-44030

Disclosure Date: October 02, 2024 (last updated October 05, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP allows PHP Local File Inclusion.This issue affects Checkout Mestres WP: from n/a through 8.6.
0
Attacker Value
Unknown

CVE-2024-43315

Disclosure Date: August 18, 2024 (last updated August 19, 2024)
Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.
0
Attacker Value
Unknown

CVE-2023-47681

Disclosure Date: June 19, 2024 (last updated June 20, 2024)
Missing Authorization vulnerability in QuadLayers WooCommerce Checkout Manager.This issue affects WooCommerce Checkout Manager: from n/a through 7.3.0.
0
Attacker Value
Unknown

CVE-2024-4632

Disclosure Date: June 19, 2024 (last updated January 05, 2025)
The WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2023-51671

Disclosure Date: June 12, 2024 (last updated July 19, 2024)
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
Attacker Value
Unknown

CVE-2023-51670

Disclosure Date: June 12, 2024 (last updated July 19, 2024)
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
Attacker Value
Unknown

CVE-2024-35658

Disclosure Date: June 10, 2024 (last updated June 13, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro) allows Functionality Misuse, File Manipulation.This issue affects Checkout Field Editor for WooCommerce (Pro): from n/a through 3.6.2.
Attacker Value
Unknown

CVE-2024-31267

Disclosure Date: June 09, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2.
Attacker Value
Unknown

CVE-2024-1718

Disclosure Date: June 04, 2024 (last updated January 05, 2025)
The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_order_status() function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the status of orders to paid bypassing payment.
0