Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2023-32240

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Xtemos WoodMart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WoodMart: from n/a through 7.2.1.
0
Attacker Value
Unknown

CVE-2024-12333

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_instagram_ajax_query AJAX action. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2023-32244

Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Improper Privilege Management vulnerability in XTemos Woodmart Core allows Privilege Escalation.This issue affects Woodmart Core: from n/a through 1.0.36.
0
Attacker Value
Unknown

CVE-2023-25790

Disclosure Date: April 24, 2024 (last updated April 25, 2024)
Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart allows Cross-Site Scripting (XSS).This issue affects WoodMart: from n/a through 7.0.4.
0
Attacker Value
Unknown

CVE-2023-32242

Disclosure Date: December 21, 2023 (last updated February 25, 2025)
Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.
Attacker Value
Unknown

CVE-2023-32500

Disclosure Date: November 09, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme <= 7.1.1 versions.
Attacker Value
Unknown

CVE-2023-41872

Disclosure Date: September 25, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xtemos WoodMart plugin <= 7.2.4 versions.
Attacker Value
Unknown

CVE-2023-32239

Disclosure Date: June 22, 2023 (last updated February 25, 2025)
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in xtemos WoodMart theme <= 7.2.1 versions.