CVE-2023-35881 – WordPress WooCommerce One Page Checkout plugin <= 2.3.0 - Local File Inclusion vulnerability
https://notcve.org/view.php?id=CVE-2023-35881
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0. Limitación incorrecta de un nombre de ruta a una vulnerabilidad de directorio restringido ("Path Traversal") en WooCommerce WooCommerce One Page Checkout permite la inclusión de archivos locales PHP. Este problema afecta a WooCommerce One Page Checkout: desde n/a hasta 2.3.0. The WooCommerce One Page Checkout plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.0 via the 'woocommerce_one_page_checkout' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. • https://patchstack.com/database/vulnerability/woocommerce-one-page-checkout/wordpress-woocommerce-one-page-checkout-plugin-2-3-0-local-file-inclusion-vulnerability?_s_id=cve • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') •
CVE-2023-37989 – Easyship WooCommerce Shipping Rates <= 0.8.9 - Missing Authorization via multiple AJAX actions
https://notcve.org/view.php?id=CVE-2023-37989
The Easyship WooCommerce Shipping Rates plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to missing capability checks on multiple AJAX functions in versions up to, and including, 0.8.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to register for and deactivate EasyShip functionality. • CWE-862: Missing Authorization •
CVE-2023-37975 – WordPress Variation Swatches for WooCommerce Plugin <= 2.3.7 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-37975
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Swatches for WooCommerce plugin <= 2.3.7 versions. The Variation Swatches for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the last active tab value in versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/woo-product-variation-swatches/wordpress-variation-swatches-for-woocommerce-plugin-2-3-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-37873 – WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.5 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-37873
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions. Se ha encontrado una vulnerabilidad de Cross-Site Scripting (XSS) reflejado sin necesidad de autenticación en el plugin WooCommerce Shipping Multiple Addresses en versiones anteriores, e incluyendo, la 3.8.5. The WooCommerce Ship to Multiple Addresses plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/woocommerce-shipping-multiple-addresses/wordpress-woocommerce-ship-to-multiple-addresses-plugin-3-8-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-37870 – WordPress WooCommerce Warranty Requests plugin <= 2.1.9 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2023-37870
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9. Vulnerabilidad de autorización faltante en Woo WooCommerce Warranty Requests. Este problema afecta a WooCommerce Warranty Requests: desde n/a hasta 2.1.9. The WooCommerce Warranty Requests plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on one of its functions in versions up to, and including, 2.1.9. This makes it possible for authenticated attackers, with customer-level access and above, to make use of this functionality intended for higher-privileged users. • https://patchstack.com/database/vulnerability/woocommerce-warranty/wordpress-woocommerce-warranty-requests-plugin-2-1-9-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •