Show filters
69 Total Results
Displaying 21-30 of 69
Sort by:
Attacker Value
Unknown
CVE-2024-1718
Disclosure Date: June 04, 2024 (last updated January 05, 2025)
The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_order_status() function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the status of orders to paid bypassing payment.
0
Attacker Value
Unknown
CVE-2024-30527
Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.
0
Attacker Value
Unknown
CVE-2023-35881
Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0.
0
Attacker Value
Unknown
CVE-2022-45070
Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3.
0
Attacker Value
Unknown
CVE-2024-33956
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.
0
Attacker Value
Unknown
CVE-2024-2752
Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The Where Did You Hear About Us Checkout Field for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via order meta in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-0629
Disclosure Date: May 02, 2024 (last updated May 03, 2024)
The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sniff_ins function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to make changes to orders and mark them as paid.
0
Attacker Value
Unknown
CVE-2023-51472
Disclosure Date: April 24, 2024 (last updated April 25, 2024)
Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7.
0
Attacker Value
Unknown
CVE-2023-51471
Disclosure Date: April 24, 2024 (last updated April 25, 2024)
Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7.
0
Attacker Value
Unknown
CVE-2024-32571
Disclosure Date: April 18, 2024 (last updated April 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 WP Stripe Checkout allows Stored XSS.This issue affects WP Stripe Checkout: from n/a through 1.2.2.41.
0