Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

W2s MEDIUM 6.5
CVE-2024-12861

The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via th…

Fix: 1.3.0+
Fix from $1,600 2025-01-30
Woocommerce Photo Reviews CRITICAL 9.8
CVE-2024-8277

The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. Thi…

Fix: 1.3.14+
Fix from $2,300 2024-09-11
Woocommerce Thank You Page Customizer MEDIUM 5.4
CVE-2024-1687

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized execution of shortcodes due to…

Fix: after 1.1.3
Fix from $1,600 2024-02-27
Curcy MEDIUM 5.4
CVE-2023-50831

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY – Multi Currency for WooCommer…

Fix: after 2.2.0
Fix from $1,600 2023-12-21
Product Size Chart For Woocommerce HIGH 8.8
CVE-2023-48778

Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Product Size Chart For WooCommerce.This issue affects Product Size Chart For WooCommerc…

Fix: after 1.1.5
Fix from $1,950 2023-12-18
Wpbulky MEDIUM 5.4
CVE-2023-30482

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in VillaTheme WPBulky plugin <= 1.0.10 versions.

Fix: 1.0.10+
Fix from $1,600 2023-08-08
Abandoned Cart Recovery For Woocommerce MEDIUM 6.5
CVE-2021-4395

The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.4.…

Fix: after 1.0.4
Fix from $1,600 2023-07-01
Woocommerce Multi Currency MEDIUM 6.5
CVE-2021-4379

The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmc_bulk_fixed_pri…

Fix: 2.1.18+
Fix from $1,600 2023-06-07
Woocommerce Thank You Page Customizer HIGH 8.8
CVE-2022-46810

Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin <= 1.0.13 versio…

Fix: after 1.0.13
Fix from $1,950 2023-05-25
Woocommerce Thank You Page Customizer HIGH 8.8
CVE-2022-46812

Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin <= 1.0.13 versio…

Fix: after 1.0.13
Fix from $1,950 2023-05-25
Dropshipping And Fulfillment For Aliexpress And Woocommerce HIGH 7.5
CVE-2022-41623

Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress.

Fix: after 1.1.0
Fix from $1,950 2022-10-14
Exmage HIGH 7.2
CVE-2022-1037

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by usi…

Fix: 1.0.7+
Fix from $1,950 2022-04-18
Orders Tracking For Woocommerce MEDIUM 6.1
CVE-2021-25062

The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin pa…

Fix: 1.1.10+
Fix from $1,600 2022-01-24