Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Woocommerce Support Ticket System MEDIUM 5.4
CVE-2024-13775

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on …

Fix: 17.9+
Fix from $1,600 2025-02-01
Woocommerce Customers Manager HIGH 8.8
CVE-2024-13343

The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new…

Fix: 31.4+
Fix from $1,950 2025-02-01
User Extra Fields CRITICAL 9.8
CVE-2024-11150

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_…

Fix: 16.7+
Fix from $2,300 2024-11-13
User Extra Fields HIGH 8.8
CVE-2024-10800

The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields(…

Fix: 16.7+
Fix from $1,950 2024-11-13
Woocommerce Upload Files CRITICAL 9.8
CVE-2024-10820

The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() f…

Fix: 84.4+
Fix from $2,300 2024-11-13
Woocommerce Support Ticket System CRITICAL 9.8
CVE-2024-10627

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_ma…

Fix: 17.8+
Fix from $2,300 2024-11-09
Woocommerce Support Ticket System CRITICAL 9.1
CVE-2024-10625

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the d…

Fix: 17.8+
Fix from $2,300 2024-11-09
Woocommerce Support Ticket System HIGH 8.1
CVE-2024-10626

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the d…

Fix: 17.8+
Fix from $1,950 2024-11-09
Woocommerce Customers Manager HIGH 8.1
CVE-2024-3983

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make lo…

Fix: 30.1+
Fix from $1,950 2024-08-01
Woocommerce Customers Manager MEDIUM 6.5
CVE-2024-2843

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged i…

Fix: 30.1+
Fix from $1,600 2024-08-01
Woocommerce Customers Manager MEDIUM 6.5
CVE-2024-1747

The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticat…

Fix: 30.2+
Fix from $1,600 2024-08-01
Woocommerce Customers Manager MEDIUM 6.5
CVE-2024-1756

The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated use…

Fix: 29.8+
Fix from $1,600 2024-04-24
Woocommerce Customers Manager MEDIUM 5.9
CVE-2024-1743

The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before outputting them back in pages a…

Fix: 29.8+
Fix from $1,600 2024-04-24
Woocommerce Customers Manager HIGH 8.1
CVE-2024-0399

The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, …

Fix: 29.7+
Fix from $1,950 2024-04-15
Woocommerce Upload Files CRITICAL 9.8
CVE-2021-24171

The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible t…

Fix: 59.4+
Fix from $2,300 2021-04-05