CusRev records
13 published records for vendor cusrev.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 23.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-6979No exploit | Customer Reviews for WooCommerce <= 5.38.9 - Authenticated (Author+) Arbitrary File Uploadcusrev · customer reviews for woocommerce · CWE-434 | High8.8 | — | 1.1% | Jan 11, 2024 |
35Monitor | CVE-2023-0080No exploit | Customer Reviews for WooCommerce < 5.16.0 - Contributor+ LFIcusrev · customer reviews for woocommerce · CWE-22 | High8.8 | — | 1.1% | Feb 13, 2023 |
35Monitor | CVE-2022-38134No exploit | WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Authenticated Broken Access Control vulnerabilitycusrev · customer reviews for woocommerce · CWE-264 | High8.8 | — | 1.0% | Sep 23, 2022 |
35Monitor | CVE-2022-38470No exploit | WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Cross-Site Request Forgery (CSRF) vulnerabilitycusrev · customer reviews for woocommerce · CWE-352 | High8.8 | — | 0.4% | Sep 23, 2022 |
30Monitor | CVE-2022-40194No exploit | WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Sensitive Information Disclosure vulnerabilitycusrev · customer reviews for woocommerce · CWE-200 | High7.5 | — | 0.9% | Sep 23, 2022 |
24Monitor | CVE-2024-3731No exploit | Customer Reviews for WooCommerce <= 5.47.0 - Reflected Cross-Site Scripting via 's'cusrev · customer reviews for woocommerce · CWE-79 | Medium6.1 | — | 0.4% | Apr 18, 2024 |
21Monitor | CVE-2023-0079No exploit | Customer Reviews for WooCommerce < 5.17.0 - Contributor+ Stored XSScusrev · customer reviews for woocommerce · CWE-79 | Medium5.4 | — | 0.5% | Jan 16, 2024 |
21Monitor | CVE-2024-1044No exploit | Customer Reviews for WooCommerce <= 5.38.10 - Improper Authorization via submit_reviewcusrev · customer reviews for woocommerce · CWE-284 | Medium5.3 | — | 0.4% | Feb 28, 2024 |
17Monitor | CVE-2024-3869No exploit | Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Coupon Searchcusrev · customer reviews for woocommerce · CWE-862 | Medium4.3 | — | 0.5% | Apr 16, 2024 |
17Monitor | CVE-2024-3243No exploit | Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sendingcusrev · customer reviews for woocommerce · CWE-862 | Medium4.3 | — | 0.4% | Apr 16, 2024 |
17Monitor | CVE-2023-51692No exploit | WordPress Customer Reviews for WooCommerce Plugin <= 5.38.1 is vulnerable to Broken Access Controlcusrev · customer reviews for woocommerce · CWE-862 | Medium4.3 | — | 0.3% | Feb 28, 2024 |
17Monitor | CVE-2023-45101No exploit | WordPress Customer Reviews for WooCommerce plugin <= 5.36.0 - Broken Access Control vulnerabilitycusrev · customer reviews for woocommerce · CWE-862 | Medium4.3 | — | 0.3% | Jan 2, 2025 |
17Monitor | CVE-2024-10614No exploit | Customer Reviews for WooCommerce <= 5.61.0 - Missing Authorization to Authenticated (Subscriber+) Import Cancellationcusrev · customer reviews for woocommerce · CWE-862 | Medium4.3 | — | 0.3% | Nov 16, 2024 |
- CVE-2023-697935Monitor
Customer Reviews for WooCommerce <= 5.38.9 - Authenticated (Author+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%cusrev · customer reviews for woocommerceJan 11, 2024
- CVE-2023-008035Monitor
Customer Reviews for WooCommerce < 5.16.0 - Contributor+ LFI
HighCVSS 8.8No exploitEPSS 1%cusrev · customer reviews for woocommerceFeb 13, 2023
- CVE-2022-3813435Monitor
WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Authenticated Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%cusrev · customer reviews for woocommerceSep 23, 2022
- CVE-2022-3847035Monitor
WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Cross-Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%cusrev · customer reviews for woocommerceSep 23, 2022
- CVE-2022-4019430Monitor
WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Sensitive Information Disclosure vulnerability
HighCVSS 7.5No exploitEPSS 1%cusrev · customer reviews for woocommerceSep 23, 2022
- CVE-2024-373124Monitor
Customer Reviews for WooCommerce <= 5.47.0 - Reflected Cross-Site Scripting via 's'
MediumCVSS 6.1No exploitEPSS 0%cusrev · customer reviews for woocommerceApr 18, 2024
- CVE-2023-007921Monitor
Customer Reviews for WooCommerce < 5.17.0 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%cusrev · customer reviews for woocommerceJan 16, 2024
- CVE-2024-104421Monitor
Customer Reviews for WooCommerce <= 5.38.10 - Improper Authorization via submit_review
MediumCVSS 5.3No exploitEPSS 0%cusrev · customer reviews for woocommerceFeb 28, 2024
- CVE-2024-386917Monitor
Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Coupon Search
MediumCVSS 4.3No exploitEPSS 0%cusrev · customer reviews for woocommerceApr 16, 2024
- CVE-2024-324317Monitor
Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending
MediumCVSS 4.3No exploitEPSS 0%cusrev · customer reviews for woocommerceApr 16, 2024
- CVE-2023-5169217Monitor
WordPress Customer Reviews for WooCommerce Plugin <= 5.38.1 is vulnerable to Broken Access Control
MediumCVSS 4.3No exploitEPSS 0%cusrev · customer reviews for woocommerceFeb 28, 2024
- CVE-2023-4510117Monitor
WordPress Customer Reviews for WooCommerce plugin <= 5.36.0 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%cusrev · customer reviews for woocommerceJan 2, 2025
- CVE-2024-1061417Monitor
Customer Reviews for WooCommerce <= 5.61.0 - Missing Authorization to Authenticated (Subscriber+) Import Cancellation
MediumCVSS 4.3No exploitEPSS 0%cusrev · customer reviews for woocommerceNov 16, 2024