3 results (0.003 seconds)

CVSS: 5.3EPSS: %CPEs: 1EXPL: 0

The Persian WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.1.6. This makes it possible for unauthenticated attackers to perform an unauthorized action. • CWE-862: Missing Authorization •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue El plugin Persian Woocommerce de WordPress versiones hasta 5.8.0, no escapa el parámetro s antes de devolverlo en un atributo en el panel de administración, lo que podría conllevar un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/1980c5ca-447d-4875-b542-9212cc7ff77f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS. El plugin persian-woocommerce-sms versiones anteriores a 3.3.4 para WordPress, presenta una vulnerabilidad de tipo XSS del parámetro ps_sms_numbers. The persian-woocommerce-sms plugin before 3.3.3 for WordPress has ps_sms_numbers XSS. • https://0x62626262.wordpress.com/2016/04/21/persian-woocommerce-sms-xss-vulnerability https://wordpress.org/plugins/persian-woocommerce-sms/#developers https://wpvulndb.com/vulnerabilities/8463 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •