Show filters
100 Total Results
Displaying 11-20 of 100
Sort by:
Attacker Value
Unknown

CVE-2023-34003

Disclosure Date: June 09, 2024 (last updated October 12, 2024)
Missing Authorization vulnerability in Woo WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.1.51.
Attacker Value
Unknown

CVE-2023-51494

Disclosure Date: June 09, 2024 (last updated November 06, 2024)
Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1.
Attacker Value
Unknown

CVE-2024-33628

Disclosure Date: June 04, 2024 (last updated June 05, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows PHP Local File Inclusion.This issue affects XforWooCommerce: from n/a through 2.0.2.
0
Attacker Value
Unknown

CVE-2023-35881

Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0.
0
Attacker Value
Unknown

CVE-2024-32517

Disclosure Date: April 17, 2024 (last updated April 17, 2024)
Missing Authorization vulnerability in WooCommerce & WordPress Tutorials Custom Thank You Page Customize For WooCommerce by Binary Carpenter.This issue affects Custom Thank You Page Customize For WooCommerce by Binary Carpenter: from n/a through 1.4.12.
0
Attacker Value
Unknown

CVE-2023-51499

Disclosure Date: April 12, 2024 (last updated April 13, 2024)
Missing Authorization vulnerability in WooCommerce WooCommerce Shipping Per Product.This issue affects WooCommerce Shipping Per Product: from n/a through 2.5.4.
0
Attacker Value
Unknown

CVE-2023-44999

Disclosure Date: March 27, 2024 (last updated April 02, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.0.
0
Attacker Value
Unknown

CVE-2024-24799

Disclosure Date: March 26, 2024 (last updated April 02, 2024)
Missing Authorization vulnerability in WooCommerce WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.2.2.
0
Attacker Value
Unknown

CVE-2023-4703

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.
Attacker Value
Unknown

CVE-2022-0775

Disclosure Date: January 16, 2024 (last updated January 20, 2024)
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment