CVE-2023-37975 – WordPress Variation Swatches for WooCommerce Plugin <= 2.3.7 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-37975
12 Jul 2023 — Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Swatches for WooCommerce plugin <= 2.3.7 versions. The Variation Swatches for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the last active tab value in versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a... • https://patchstack.com/database/vulnerability/woo-product-variation-swatches/wordpress-variation-swatches-for-woocommerce-plugin-2-3-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-37870 – WordPress WooCommerce Warranty Requests plugin <= 2.1.9 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2023-37870
10 Jul 2023 — Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9. Vulnerabilidad de autorización faltante en Woo WooCommerce Warranty Requests. Este problema afecta a WooCommerce Warranty Requests: desde n/a hasta 2.1.9. The WooCommerce Warranty Requests plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on one of its functions in versions up to, and including, 2.1.9. This ... • https://patchstack.com/database/vulnerability/woocommerce-warranty/wordpress-woocommerce-warranty-requests-plugin-2-1-9-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •
CVE-2023-37872 – WordPress WooCommerce Ship to Multiple Addresses plugin <= 3.8.5 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2023-37872
10 Jul 2023 — Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.5. Vulnerabilidad de autorización faltante en Woo WooCommerce Ship to Multiple Addresses. Este problema afecta a WooCommerce Ship to Multiple Addresses: desde n/a hasta 3.8.5. The WooCommerce Ship to Multiple Addresses plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on one of its functions i... • https://patchstack.com/database/vulnerability/woocommerce-shipping-multiple-addresses/wordpress-woocommerce-ship-to-multiple-addresses-plugin-3-8-5-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •
CVE-2023-37971 – WordPress WooCommerce Product Stock Alert plugin <= 2.0.1 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2023-37971
10 Jul 2023 — Missing Authorization vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Product Stock Alert: from n/a through 2.0.1. The WooCommerce Product Stock Alert plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stock_alert_rest_routes_react_module action in versions up to, and including, 2.0.1. This makes it possible for authenticated attackers w... • https://patchstack.com/database/wordpress/plugin/woocommerce-product-stock-alert/vulnerability/wordpress-woocommerce-product-stock-alert-plugin-2-0-1-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •
CVE-2023-3507 – WooCommerce Pre-Orders < 2.0.3 - Arbitrary Pre-Order Canceling via CSRF
https://notcve.org/view.php?id=CVE-2023-3507
10 Jul 2023 — The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to cancel pre-orders via a forged request ... • https://wpscan.com/vulnerability/e72bbe9b-e51d-40ab-820d-404e0cb86ee6 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2023-3508 – WooCommerce Pre-Orders < 2.0.3 - Unauthorised Actions via CSRF
https://notcve.org/view.php?id=CVE-2023-3508
10 Jul 2023 — The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on several of its functio... • https://wpscan.com/vulnerability/064c7acb-db57-4537-8a6d-32f7ea31c738 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2023-37873 – WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.5 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-37873
10 Jul 2023 — Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions. Se ha encontrado una vulnerabilidad de Cross-Site Scripting (XSS) reflejado sin necesidad de autenticación en el plugin WooCommerce Shipping Multiple Addresses en versiones anteriores, e incluyendo, la 3.8.5. The WooCommerce Ship to Multiple Addresses plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.8.5 due to insufficient inp... • https://patchstack.com/database/vulnerability/woocommerce-shipping-multiple-addresses/wordpress-woocommerce-ship-to-multiple-addresses-plugin-3-8-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-3525 – Getnet Argentina para Woocommerce 0.0.1 - 0.0.4 - Authorization Bypass via webhook
https://notcve.org/view.php?id=CVE-2023-3525
07 Jul 2023 — The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment. • https://www.wordfence.com/threat-intel/vulnerabilities/id/245e9117-ca63-458e-a094-60a759f5ec19?source=cve • CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2023-36511 – WordPress WooCommerce Order Barcodes Plugin <= 1.6.4 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-36511
26 Jun 2023 — Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Order Barcodes plugin <= 1.6.4 versions. The WooCommerce Order Barcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action via a forged request granted they can trick a site administrator into performing an action such as c... • https://patchstack.com/database/vulnerability/woocommerce-order-barcodes/wordpress-woocommerce-order-barcodes-plugin-1-6-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2023-36513 – WordPress AutomateWoo Plugin <= 5.7.5 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-36513
26 Jun 2023 — Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions. The AutomateWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.5. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Cross-... • https://patchstack.com/database/vulnerability/automatewoo/wordpress-automatewoo-plugin-5-7-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •