Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yith Woocommerce Product Add Ons MEDIUM 6.1
CVE-2024-50448

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-…

Fix: 4.14.2+
Fix from $1,600 2024-10-28
Yith Woocommerce Ajax Search MEDIUM 5.4
CVE-2024-7846

YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it p…

Fix: 2.7.1+
Fix from $1,600 2024-09-23
Yith Custom Login MEDIUM 6.1
CVE-2024-8665

The YITH Custom Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escapi…

Fix: 1.7.4+
Fix from $1,600 2024-09-13
Yith Woocommerce Product Add Ons MEDIUM 5.3
CVE-2024-35680

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocomm…

Fix: 4.9.3+
Fix from $1,600 2024-06-10
Woocommerce Account Funds HIGH 8.8
CVE-2024-30470

Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/…

Fix: 1.34.0+
Fix from $1,950 2024-06-09
Yith Woocommerce Ajax Search MEDIUM 6.1
CVE-2024-4455

The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and in…

Fix: 2.4.1+
Fix from $1,600 2024-05-24
Yith Woocommerce Product Add Ons HIGH 8.8
CVE-2023-49777

Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/…

Fix: after 4.3.0
Fix from $1,950 2023-12-31
Yith Woocommerce Gift Cards CRITICAL 9.8
CVE-2022-45359EPSS 14%

Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.

Fix: after 3.19.0
Fix from $2,300 2022-12-06
Woocommerce Affiliate MEDIUM 6.1
CVE-2022-0818

The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well a…

Fix: 4.16.4.5+
Fix from $1,600 2022-03-28
Yith Maintenance Mode MEDIUM 5.4
CVE-2021-36841

Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yi…

Fix: after 1.3.7
Fix from $1,600 2021-09-27
Yith Woocommerce Gift Cards CRITICAL 9.8
CVE-2021-3120EPSS 37%

An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achiev…

Fix: 3.3.1+
Fix from $2,300 2021-02-22
Yith Maintenance Mode MEDIUM 6.5
CVE-2015-9429

The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_…

Fix: 1.2.0+
Fix from $1,600 2019-09-26