Page 31 of 250 results (0.003 seconds)

CVSS: 4.3EPSS: %CPEs: 1EXPL: 0

The YITH WooCommerce Waiting List plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.0. This is due to missing or incorrect nonce validation on the 'save_mail_status' function. This makes it possible for unauthenticated attackers to enable or disable email notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. • CWE-862: Missing Authorization •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0. Limitación incorrecta de un nombre de ruta a una vulnerabilidad de directorio restringido ("Path Traversal") en WooCommerce WooCommerce One Page Checkout permite la inclusión de archivos locales PHP. Este problema afecta a WooCommerce One Page Checkout: desde n/a hasta 2.3.0. The WooCommerce One Page Checkout plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.0 via the 'woocommerce_one_page_checkout' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. • https://patchstack.com/database/vulnerability/woocommerce-one-page-checkout/wordpress-woocommerce-one-page-checkout-plugin-2-3-0-local-file-inclusion-vulnerability?_s_id=cve • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

The Easyship WooCommerce Shipping Rates plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to missing capability checks on multiple AJAX functions in versions up to, and including, 0.8.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to register for and deactivate EasyShip functionality. • CWE-862: Missing Authorization •

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Swatches for WooCommerce plugin <= 2.3.7 versions. The Variation Swatches for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the last active tab value in versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/woo-product-variation-swatches/wordpress-variation-swatches-for-woocommerce-plugin-2-3-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

The WooCommerce Product Stock Alert plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stock_alert_rest_routes_react_module action in versions up to, and including, 2.0.1. This makes it possible for authenticated attackers with subscriber-level access to use this endpoint intended for administrators. • CWE-862: Missing Authorization •