Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Back Button Widget MEDIUM 5.4
CVE-2025-48252

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget back-button-widget…

Fix: after 1.6.8
Fix from $1,600 2025-05-19
Free Shipping Bar MEDIUM 5.4
CVE-2025-48253

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shipping Bar: Amount Left for Fr…

Fix: after 2.4.6
Fix from $1,600 2025-05-19
Change Add To Cart Button Text For Woocommerce MEDIUM 5.4
CVE-2025-48254

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for Wo…

Fix: after 2.2.2
Fix from $1,600 2025-05-19
Wishlist For Woocommerce MEDIUM 6.5
CVE-2024-13774

The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an…

Fix: 3.1.8+
Fix from $1,600 2025-03-08
Customer Email Verification For Woocommerce MEDIUM 6.5
CVE-2024-13525

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu…

Fix: 2.9.5+
Fix from $1,600 2025-02-15
Customer Email Verification For Woocommerce HIGH 7.5
CVE-2024-13528

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9…

Fix: 2.9.6+
Fix from $1,950 2025-02-12
Wishlist For Woocommerce MEDIUM 6.1
CVE-2024-10519

The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' pa…

Fix: 3.1.3+
Fix from $1,600 2024-11-23
Eu\/uk Vat Manager For Woocommerce MEDIUM 6.1
CVE-2024-44061

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EU/UK VAT Manager for WooCommerce eu-…

Fix: 3.0.0+
Fix from $1,600 2024-10-20
Products\, Order \& Customers Export For Woocommerce MEDIUM 6.1
CVE-2024-9377

The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que…

Fix: 2.1.0+
Fix from $1,600 2024-10-10
Maximum Products Per User For Woocommerce MEDIUM 6.1
CVE-2024-9205

The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wi…

Fix: 4.2.9+
Fix from $1,600 2024-10-10
Quantity Dynamic Pricing \& Bulk Discounts For Woocommerce MEDIUM 6.1
CVE-2024-9384

The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of …

Fix: 3.8.1+
Fix from $1,600 2024-10-04
Eu\/uk Vat Manager For Woocommerce MEDIUM 6.1
CVE-2024-8788

The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ap…

Fix: 2.12.14+
Fix from $1,600 2024-09-28
Eu\/uk Vat Manager For Woocommerce MEDIUM 5.3
CVE-2024-9189

The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th…

Fix: 2.12.14+
Fix from $1,600 2024-09-28
Wpfactory Helper MEDIUM 6.1
CVE-2024-8656

The WPFactory Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escapin…

Fix: 1.7.1+
Fix from $1,600 2024-09-13
Products\, Order \& Customers Export For Woocommerce CRITICAL 9.8
CVE-2024-31276

Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Ex…

Fix: 2.0.9+
Fix from $2,300 2024-06-09
Ean For Woocommerce HIGH 7.2
CVE-2024-34370

Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from…

Fix: 4.9.0+
Fix from $1,950 2024-05-17
Ean For Woocommerce MEDIUM 5.4
CVE-2023-6892

The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all…

Fix: 4.9.3+
Fix from $1,600 2024-04-18
Cost Of Goods For Woocommerce MEDIUM 6.1
CVE-2024-0821

The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the …

Fix: 3.2.9+
Fix from $1,600 2024-02-29
Back Button Widget MEDIUM 5.4
CVE-2023-51399

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget allows Stored XSS.…

Fix: after 1.6.3
Fix from $1,600 2023-12-29
Products\, Order \& Customers Export For Woocommerce MEDIUM 6.1
CVE-2023-47547

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions.

Fix: after 2.0.7
Fix from $1,600 2023-11-14
Wpfactory Helper MEDIUM 6.1
CVE-2023-36689

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory WPFactory Helper plugin <= 1.5.2 versions.

Fix: after 1.5.2
Fix from $1,600 2023-08-05
Ean For Woocommerce MEDIUM 5.4
CVE-2023-0062

The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a …

Fix: 4.4.3+
Fix from $1,600 2023-02-06
Download Plugins And Themes From Dashboard MEDIUM 6.1
CVE-2019-17239

includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthent…

Fix: after 1.5.0
Fix from $1,600 2019-10-07