Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Order Delivery Date For Woocommerce HIGH 7.1
CVE-2025-2929

The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a R…

Fix: 12.4.0+
Fix from $1,950 2025-05-20
Order Delivery Date Pro For Woocommerce CRITICAL 9.8
CVE-2025-2907

The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks…

Fix: 12.3.1+
Fix from $2,300 2025-04-26
Product Input Fields For Woocommerce CRITICAL 9.8
CVE-2024-13359

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the…

Fix: 1.12.2+
Fix from $2,300 2025-03-08
Arconix Shortcodes MEDIUM 5.4
CVE-2024-56242

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-short…

Fix: 2.1.5+
Fix from $1,600 2025-01-02
Print Invoice \& Delivery Notes For Woocommerce MEDIUM 6.5
CVE-2022-46795

Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access…

Fix: 4.7.3+
Fix from $1,600 2024-12-13
Product Input Fields For Woocommerce MEDIUM 6.5
CVE-2024-10857

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the …

Fix: 2.0+
Fix from $1,600 2024-11-26
Arconix Faq MEDIUM 5.3
CVE-2024-38783

Missing Authorization vulnerability in Tyche Softwares Arconix FAQ allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects…

Fix: 1.9.5+
Fix from $1,600 2024-11-01
Arconix Shortcodes MEDIUM 5.3
CVE-2024-38769

Missing Authorization vulnerability in Tyche Softwares Arconix Shortcodes allows Accessing Functionality Not Properly Constrained by ACLs.This issue …

Fix: 2.1.12+
Fix from $1,600 2024-11-01
Arconix Shortcodes MEDIUM 5.4
CVE-2024-10226

The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and …

Fix: 2.1.14+
Fix from $1,600 2024-10-29
Arconix Shortcodes MEDIUM 5.4
CVE-2024-9703

The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, a…

Fix: 2.1.13+
Fix from $1,600 2024-10-18
Product Delivery Date For Woocommerce MEDIUM 6.1
CVE-2024-9345

The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg…

Fix: 2.7.4+
Fix from $1,600 2024-10-04
Order Delivery Date For Wp E Commerce MEDIUM 6.1
CVE-2024-0678

The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'available-days-tf' parameter in …

Fix: after 1.2
Fix from $1,600 2024-02-05
Print Invoice \& Delivery Notes For Woocommerce MEDIUM 6.1
CVE-2023-0479

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin no…

Fix: 4.7.2+
Fix from $1,600 2024-01-16
Order Delivery Date For Woocommerce HIGH 8.8
CVE-2023-41858

Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions.

Fix: after 1.2
Fix from $1,950 2023-10-10
Order Delivery Date For Woocommerce MEDIUM 6.1
CVE-2023-41874

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin <= 3.20.0 versions.

Fix: after 3.20.0
Fix from $1,600 2023-09-25
Abandoned Cart Lite For Woocommerce MEDIUM 6.1
CVE-2019-25152

The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting vi…

Fix: 5.2.0+
Fix from $1,600 2023-06-22
Abandoned Cart Lite For Woocommerce CRITICAL 9.8
CVE-2023-2986EPSS 43%

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is…

Fix: after 5.14.2
Fix from $2,300 2023-06-08
Product Input Fields For Woocommerce HIGH 7.5
CVE-2020-36696

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_d…

Fix: 1.2.7+
Fix from $1,950 2023-06-07
Custom Order Numbers For Woocommerce HIGH 8.8
CVE-2022-45367

Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Custom Order Numbers for WooCommerce plugin <= 1.4.0 versions.

Fix: after 1.4.0
Fix from $1,950 2023-05-25
Arconix Shortcodes MEDIUM 5.4
CVE-2023-23703

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Arconix Shortcodes plugin <= 2.1.7 versions.

Fix: after 2.1.7
Fix from $1,600 2023-05-16