CVE-2024-3032 – Themify Builder < 7.5.8 - Open Redirect
https://notcve.org/view.php?id=CVE-2024-3032
Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue El complemento Themify Builder de WordPress anterior a 7.5.8 no valida un parámetro antes de redirigir al usuario a su valor, lo que genera un problema de Open Redirect The Themify Builder plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.5.7. This is due to insufficient validation on the redirect url supplied via the 'tb_redirect_fail' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action. • https://wpscan.com/vulnerability/d130a60c-c36b-4994-9b0e-e52cd7f99387 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2024-2262 – WooCommerce Product Filter < 1.4.4 - Filter Deletion via CSRF
https://notcve.org/view.php?id=CVE-2024-2262
Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs El complemento Themify de WordPress anterior a 1.4.4 no tiene verificación CSRF en su acción masiva, lo que podría permitir a los atacantes hacer que los usuarios registrados eliminen filtros arbitrarios mediante un ataque CSRF, siempre que conozcan los filtros relacionados. The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.3. This is due to missing or incorrect nonce validation on the wpf_search page. This makes it possible for unauthenticated attackers to delete arbitrary filters via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/30544377-b90d-4762-b38a-ec89bda0dfdc • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2024-2263 – WooCommerce Product Filter < 1.4.4 - Reflected XSS
https://notcve.org/view.php?id=CVE-2024-2263
Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin El complemento Themify de WordPress anterior a 1.4.4 no sanitiza ni escapa un parámetro antes de devolverlo a la página, lo que genera una cross-site scripting reflejado que podría usarse contra usuarios con altos privilegios, como el administrador. The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/ec092ed9-eb3e-40a7-a878-ab854104e290 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-2278 – WooCommerce Product Filter < 1.4.4 - Admin+ Stored XSS
https://notcve.org/view.php?id=CVE-2024-2278
Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) El complemento Themify de WordPress anterior a 1.4.4 no sanitiza ni escapa algunas de sus configuraciones de filtros, lo que podría permitir a usuarios con privilegios elevados, como el administrador, realizar ataques de cross-site scripting almacenado incluso cuando la capacidad unfiltered_html no está permitida (por ejemplo, en una configuración multisitio). The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. • https://wpscan.com/vulnerability/2cbabde8-1e3e-4205-8a5c-b889447236a0 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •