StoreApps records
8 published records for vendor storeapps.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-25649No exploit | WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Multiple Improper Access Control vulnerabilitiesstoreapps · affiliate for woocommerce · CWE-264 | High8.8 | — | 0.9% | Aug 5, 2022 |
35Monitor | CVE-2023-5663No exploit | News Announcement Scroll <= 9.0.0 - Authenticated (Contributor+) SQL Injection via Shortcodestoreapps · news announcement scroll · CWE-89 | High8.8 | — | 0.8% | Mar 13, 2024 |
35Monitor | CVE-2021-34619No exploit | Cross-Site Request Forgery in WooCommerce Stock Manager WordPress Pluginstoreapps · stock manager for woocommerce · CWE-352 | High8.8 | — | 0.7% | Jul 21, 2021 |
35Monitor | CVE-2023-35091No exploit | WordPress WooCommerce Stock Manager Plugin <= 2.10.0 is vulnerable to Cross Site Request Forgery (CSRF)storeapps · stock manager for woocommerce · CWE-352 | High8.8 | — | 0.3% | Jul 11, 2023 |
29Monitor | CVE-2024-0566Proof of concept | Smart Manager < 8.28.0 - Admin+ SQL Injectionstoreapps · smart manager · CWE-89 | High7.2 | — | 3.3% | Feb 12, 2024 |
26Monitor | CVE-2022-36284No exploit | WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email changestoreapps · affiliate for woocommerce · CWE-639 | Medium6.5 | — | 0.6% | Aug 5, 2022 |
19Monitor | CVE-2022-40694No exploit | WordPress News Announcement Scroll plugin <= 8.8.8 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilitystoreapps · news announcement scroll · CWE-79 | Medium4.8 | — | 0.4% | Nov 17, 2022 |
17Monitor | CVE-2021-24836No exploit | Temporary Login Without Password < 1.7.1 - Subscriber+ Plugin's Settings Updatestoreapps · temporary login without password · CWE-352 | Medium4.3 | — | 0.3% | Dec 13, 2021 |
- CVE-2022-2564935Monitor
WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Multiple Improper Access Control vulnerabilities
HighCVSS 8.8No exploitEPSS 1%storeapps · affiliate for woocommerceAug 5, 2022
- CVE-2023-566335Monitor
News Announcement Scroll <= 9.0.0 - Authenticated (Contributor+) SQL Injection via Shortcode
HighCVSS 8.8No exploitEPSS 1%storeapps · news announcement scrollMar 13, 2024
- CVE-2021-3461935Monitor
Cross-Site Request Forgery in WooCommerce Stock Manager WordPress Plugin
HighCVSS 8.8No exploitEPSS 1%storeapps · stock manager for woocommerceJul 21, 2021
- CVE-2023-3509135Monitor
WordPress WooCommerce Stock Manager Plugin <= 2.10.0 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%storeapps · stock manager for woocommerceJul 11, 2023
- CVE-2024-056629Monitor
Smart Manager < 8.28.0 - Admin+ SQL Injection
HighCVSS 7.2Proof of conceptEPSS 3%storeapps · smart managerFeb 12, 2024
- CVE-2022-3628426Monitor
WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email change
MediumCVSS 6.5No exploitEPSS 1%storeapps · affiliate for woocommerceAug 5, 2022
- CVE-2022-4069419Monitor
WordPress News Announcement Scroll plugin <= 8.8.8 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%storeapps · news announcement scrollNov 17, 2022
- CVE-2021-2483617Monitor
Temporary Login Without Password < 1.7.1 - Subscriber+ Plugin's Settings Update
MediumCVSS 4.3No exploitEPSS 0%storeapps · temporary login without passwordDec 13, 2021