Show filters
378 Total Results
Displaying 31-40 of 378
Sort by:
Attacker Value
Unknown
CVE-2024-37297
Disclosure Date: June 12, 2024 (last updated July 24, 2024)
WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While the content is not saved to the database, the links may be sent to victims for malicious purposes. The injected JavaScript could hijack content & data stored in the browser, including the session. The URL content is read through the `Sourcebuster.js` library and then inserted without proper sanitization to the classic checkout and registration forms. Versions 8.8.5 and 8.9.3 contain a patch for the issue. As a workaround, one may disable the Order Attribution feature.
0
Attacker Value
Unknown
CVE-2023-34003
Disclosure Date: June 09, 2024 (last updated October 12, 2024)
Missing Authorization vulnerability in Woo WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.1.51.
0
Attacker Value
Unknown
CVE-2023-51494
Disclosure Date: June 09, 2024 (last updated November 06, 2024)
Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1.
0
Attacker Value
Unknown
CVE-2024-35676
Disclosure Date: June 08, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through 1.7.
0
Attacker Value
Unknown
CVE-2024-33628
Disclosure Date: June 04, 2024 (last updated June 05, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows PHP Local File Inclusion.This issue affects XforWooCommerce: from n/a through 2.0.2.
0
Attacker Value
Unknown
CVE-2023-35881
Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0.
0
Attacker Value
Unknown
CVE-2024-32517
Disclosure Date: April 17, 2024 (last updated April 17, 2024)
Missing Authorization vulnerability in WooCommerce & WordPress Tutorials Custom Thank You Page Customize For WooCommerce by Binary Carpenter.This issue affects Custom Thank You Page Customize For WooCommerce by Binary Carpenter: from n/a through 1.4.12.
0
Attacker Value
Unknown
CVE-2023-51499
Disclosure Date: April 12, 2024 (last updated April 13, 2024)
Missing Authorization vulnerability in WooCommerce WooCommerce Shipping Per Product.This issue affects WooCommerce Shipping Per Product: from n/a through 2.5.4.
0
Attacker Value
Unknown
CVE-2024-31360
Disclosure Date: April 12, 2024 (last updated April 13, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Coded Commerce, LLC Benchmark Email Lite.This issue affects Benchmark Email Lite: from n/a through 4.1.
0
Attacker Value
Unknown
CVE-2023-44999
Disclosure Date: March 27, 2024 (last updated April 02, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.0.
0