Show filters
100 Total Results
Displaying 91-100 of 100
Sort by:
Attacker Value
Unknown
CVE-2019-14796
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.
0
Attacker Value
Unknown
CVE-2019-7441
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state
0
Attacker Value
Unknown
CVE-2019-9168
Disclosure Date: February 26, 2019 (last updated November 27, 2024)
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
0
Attacker Value
Unknown
CVE-2018-20714
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.
0
Attacker Value
Unknown
CVE-2017-18356
Disclosure Date: January 15, 2019 (last updated October 18, 2024)
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.
0
Attacker Value
Unknown
CVE-2018-8710
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function accessible to anyone without any authentication. WordPress shortcode markup in the "shortcode" parameters would be evaluated. Normally unauthenticated users can't evaluate shortcodes as they are often sensitive.
0
Attacker Value
Unknown
CVE-2018-8711
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The vulnerability is due to the lack of args/input validation on render_html before allowing it to be called by extract(), a PHP built-in function. Because of this, the supplied args/input can be used to overwrite the $pagepath variable, which then could lead to a local file inclusion attack.
0
Attacker Value
Unknown
CVE-2015-2329
Disclosure Date: February 08, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.
0
Attacker Value
Unknown
CVE-2016-10112
Disclosure Date: January 04, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.
0
Attacker Value
Unknown
CVE-2014-4549
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MD or (2) PARes parameter.
0