Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Automatewoo HIGH 8.8
CVE-2023-36513

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions.

Fix: after 5.7.5
Fix from $1,950 2023-07-17
Shipping Multiple Addresses HIGH 8.8
CVE-2023-36514

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions.

Fix: after 3.8.5
Fix from $1,950 2023-07-17
Brands HIGH 8.8
CVE-2023-35880

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions.

Fix: 1.6.50+
Fix from $1,950 2023-07-17
Paypal Payments HIGH 8.8
CVE-2023-35917

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.

Fix: after 2.0.4
Fix from $1,950 2023-06-22
Bulk Stock Management MEDIUM 6.1
CVE-2023-35918

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Bulk Stock Management plugin <= 2.2.33 versions.

Fix: after 2.2.33
Fix from $1,600 2023-06-22
Stripe Payment Gateway HIGH 7.5
CVE-2023-34000

Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.

Fix: 7.4.1+
Fix from $1,950 2023-06-14
Sidebar Manager To Woosidebars Converter MEDIUM 6.1
CVE-2015-10115

A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affect…

Fix: after 1.1.1
Fix from $1,600 2023-06-05
Wooframework Tweaks MEDIUM 6.1
CVE-2015-10113

A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the fun…

Fix: 1.0.2+
Fix from $1,600 2023-06-05
Woosidebars MEDIUM 6.1
CVE-2015-10114

A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the fu…

Fix: 1.4.2+
Fix from $1,600 2023-06-05
Wooframework Branding MEDIUM 6.1
CVE-2015-10112

A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_scr…

Fix: after 1.0.1
Fix from $1,600 2023-06-05
Automatewoo HIGH 8.8
CVE-2023-33316

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions.

Fix: 4.9.50+
Fix from $1,950 2023-05-28
Automatewoo MEDIUM 6.1
CVE-2023-33319

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions.

Fix: after 4.9.40
Fix from $1,600 2023-05-28
Woocommerce Order Status Change Notifier MEDIUM 6.5
CVE-2023-2179

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an A…

Fix: after 1.1.0
Fix from $1,600 2023-05-15
Icons For Features MEDIUM 6.1
CVE-2015-10104

A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some …

Patch available
Fix from $1,600 2023-04-30
Persian Woocommerce MEDIUM 6.1
CVE-2021-24940

The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboa…

Fix: after 5.8.0
Fix from $1,600 2022-03-14
Woocommerce Currency Switcher MEDIUM 6.1
CVE-2021-24938

The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to …

Fix: 1.3.7.1+
Fix from $1,600 2021-12-06
Help Scout CRITICAL 9.8
CVE-2021-24212EPSS 8%

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to u…

Fix: 2.9.1+
Fix from $2,300 2021-04-05
Gift Cards HIGH 8.8
CVE-2020-35627

Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary …

No fix yet
Fix from $1,950 2020-12-28
Woocommerce MEDIUM 5.3
CVE-2020-29156

The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetc…

Fix: 4.7.0+
Fix from $1,600 2020-12-27
Nab Transact HIGH 7.5
CVE-2020-11497

An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders t…

No fix yet
Fix from $1,950 2020-08-26
Subscriptions MEDIUM 6.1
CVE-2019-18834

Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Bil…

Fix: 2.6.3+
Fix from $1,600 2020-07-23
Woocommerce HIGH 8.8
CVE-2019-20891

WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scr…

Fix: 3.6.5+
Fix from $1,950 2020-06-19
Persian Woocommerce Sms MEDIUM 6.1
CVE-2016-10987

The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.

Fix: 3.3.4+
Fix from $1,600 2019-09-17
Payu India Payment Gateway MEDIUM 5.3
CVE-2019-14978

/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 para…

No fix yet
Fix from $1,600 2019-08-29
Paypal Checkout Payment Gateway MEDIUM 5.3
CVE-2019-14979

cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount param…

No fix yet
Fix from $1,600 2019-08-29
Paypal Checkout Payment Gateway MEDIUM 6.5
CVE-2019-7441EPSS 6%

cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parame…

No fix yet
Fix from $1,600 2019-03-21
Woocommerce MEDIUM 6.1
CVE-2019-9168

WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.

Fix: 3.5.5+
Fix from $1,600 2019-02-26
Woocommerce HIGH 8.8
CVE-2017-18356

In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account th…

Fix: 3.2.4+
Fix from $1,950 2019-01-15
Woocommerce HIGH 8.1
CVE-2018-20714

The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deleti…

Fix: 3.4.6+
Fix from $1,950 2019-01-15
Woocommerce MEDIUM 6.1
CVE-2015-2329

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script …

Fix: 2.3.6+
Fix from $1,600 2018-02-08