Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-36513 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions. Automatewoo after 5.7.5 Fix from $1,9502023-07-17 HIGH 8.8 CVE-2023-36514 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions. Shipping Multiple Addresses after 3.8.5 Fix from $1,9502023-07-17 HIGH 8.8 CVE-2023-35880 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions. Brands 1.6.50+ Fix from $1,9502023-07-17 HIGH 8.8 CVE-2023-35917 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions. Paypal Payments after 2.0.4 Fix from $1,9502023-06-22 MEDIUM 6.1 CVE-2023-35918 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Bulk Stock Management plugin <= 2.2.33 versions. Bulk Stock Management after 2.2.33 Fix from $1,6002023-06-22 HIGH 7.5 CVE-2023-34000 Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions. Stripe Payment Gateway 7.4.1+ Fix from $1,9502023-06-14 MEDIUM 6.1 CVE-2015-10115 A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affect… Sidebar Manager To Woosidebars Converter after 1.1.1 Fix from $1,6002023-06-05 MEDIUM 6.1 CVE-2015-10113 A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the fun… Wooframework Tweaks 1.0.2+ Fix from $1,6002023-06-05 MEDIUM 6.1 CVE-2015-10114 A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the fu… Woosidebars 1.4.2+ Fix from $1,6002023-06-05 MEDIUM 6.1 CVE-2015-10112 A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_scr… Wooframework Branding after 1.0.1 Fix from $1,6002023-06-05 HIGH 8.8 CVE-2023-33316 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions. Automatewoo 4.9.50+ Fix from $1,9502023-05-28 MEDIUM 6.1 CVE-2023-33319 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions. Automatewoo after 4.9.40 Fix from $1,6002023-05-28 MEDIUM 6.5 CVE-2023-2179 The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an A… Woocommerce Order Status Change Notifier after 1.1.0 Fix from $1,6002023-05-15 MEDIUM 6.1 CVE-2015-10104 A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some … Icons For Features Patch available Fix from $1,6002023-04-30 MEDIUM 6.1 CVE-2021-24940 The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboa… Persian Woocommerce after 5.8.0 Fix from $1,6002022-03-14 MEDIUM 6.1 CVE-2021-24938 The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to … Woocommerce Currency Switcher 1.3.7.1+ Fix from $1,6002021-12-06 CRITICAL 9.8 CVE-2021-24212EPSS 8% The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to u… Help Scout 2.9.1+ Fix from $2,3002021-04-05 HIGH 8.8 CVE-2020-35627 Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary … Gift Cards No fix yet Fix from $1,9502020-12-28 MEDIUM 5.3 CVE-2020-29156 The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetc… Woocommerce 4.7.0+ Fix from $1,6002020-12-27 HIGH 7.5 CVE-2020-11497 An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders t… Nab Transact No fix yet Fix from $1,9502020-08-26 MEDIUM 6.1 CVE-2019-18834 Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Bil… Subscriptions 2.6.3+ Fix from $1,6002020-07-23 HIGH 8.8 CVE-2019-20891 WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scr… Woocommerce 3.6.5+ Fix from $1,9502020-06-19 MEDIUM 6.1 CVE-2016-10987 The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS. Persian Woocommerce Sms 3.3.4+ Fix from $1,6002019-09-17 MEDIUM 5.3 CVE-2019-14978 /payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 para… Payu India Payment Gateway No fix yet Fix from $1,6002019-08-29 MEDIUM 5.3 CVE-2019-14979 cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount param… Paypal Checkout Payment Gateway No fix yet Fix from $1,6002019-08-29 MEDIUM 6.5 CVE-2019-7441EPSS 6% cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parame… Paypal Checkout Payment Gateway No fix yet Fix from $1,6002019-03-21 MEDIUM 6.1 CVE-2019-9168 WooCommerce before 3.5.5 allows XSS via a Photoswipe caption. Woocommerce 3.5.5+ Fix from $1,6002019-02-26 HIGH 8.8 CVE-2017-18356 In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account th… Woocommerce 3.2.4+ Fix from $1,9502019-01-15 HIGH 8.1 CVE-2018-20714 The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deleti… Woocommerce 3.4.6+ Fix from $1,9502019-01-15 MEDIUM 6.1 CVE-2015-2329 Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script … Woocommerce 2.3.6+ Fix from $1,6002018-02-08