Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2024-13775 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on … Woocommerce Support Ticket System 17.9+ Fix from $1,6002025-02-01 HIGH 8.8 CVE-2024-13343 The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new… Woocommerce Customers Manager 31.4+ Fix from $1,9502025-02-01 CRITICAL 9.8 CVE-2024-11150 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_… User Extra Fields 16.7+ Fix from $2,3002024-11-13 HIGH 8.8 CVE-2024-10800 The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields(… User Extra Fields 16.7+ Fix from $1,9502024-11-13 CRITICAL 9.8 CVE-2024-10820 The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() f… Woocommerce Upload Files 84.4+ Fix from $2,3002024-11-13 CRITICAL 9.8 CVE-2024-10627 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_ma… Woocommerce Support Ticket System 17.8+ Fix from $2,3002024-11-09 CRITICAL 9.1 CVE-2024-10625 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the d… Woocommerce Support Ticket System 17.8+ Fix from $2,3002024-11-09 HIGH 8.1 CVE-2024-10626 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the d… Woocommerce Support Ticket System 17.8+ Fix from $1,9502024-11-09 HIGH 8.1 CVE-2024-3983 The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make lo… Woocommerce Customers Manager 30.1+ Fix from $1,9502024-08-01 MEDIUM 6.5 CVE-2024-2843 The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged i… Woocommerce Customers Manager 30.1+ Fix from $1,6002024-08-01 MEDIUM 6.5 CVE-2024-1747 The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticat… Woocommerce Customers Manager 30.2+ Fix from $1,6002024-08-01 MEDIUM 6.5 CVE-2024-1756 The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated use… Woocommerce Customers Manager 29.8+ Fix from $1,6002024-04-24 MEDIUM 5.9 CVE-2024-1743 The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before outputting them back in pages a… Woocommerce Customers Manager 29.8+ Fix from $1,6002024-04-24 HIGH 8.1 CVE-2024-0399 The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, … Woocommerce Customers Manager 29.7+ Fix from $1,9502024-04-15 CRITICAL 9.8 CVE-2021-24171 The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible t… Woocommerce Upload Files 59.4+ Fix from $2,3002021-04-05