Skip to content
Noroxi

WPFactory records

29 published records for vendor wpfactory.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
31%
Median publish → KEV
No record has entered KEV

All records

29 records
  • WordPress Products, Order & Customers Export for WooCommerce plugin <= 2.0.8 - Broken Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    wpfactory · products\, order \& customers export for woocommerceJun 9, 2024

  • WordPress Customer Email Verification for WooCommerce plugin <= 2.8.10 - SQL Injection vulnerability

    CriticalCVSS 9.3No exploitEPSS 0%

    wpfactory · email verification for woocommerceOct 17, 2024

  • CVE-2024-4185
    32Monitor

    Customer Email Verification for WooCommerce <= 2.7.4 - Email Verification and Authentication Bypass due to Insufficient Randomness

    HighCVSS 8.1No exploitEPSS 1%

    wpcodefactory · customer email verification for woocommerceApr 30, 2024

  • Customer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via Shortcode

    HighCVSS 7.5No exploitEPSS 0%

    wpfactory · customer email verification for woocommerceFeb 12, 2025

  • WordPress EAN for WooCommerce plugin <= 4.8.9 - Arbitrary Option Update to Privilege Escalation vulnerability

    HighCVSS 7.2Proof of conceptEPSS 1%

    wpfactory · ean for woocommerceMay 17, 2024

  • Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6.

    MediumCVSS 6.5No exploitEPSS 1%

    wpfactory llc · download plugins and themes from dashboardMay 22, 2024

  • Customer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure

    MediumCVSS 6.5No exploitEPSS 0%

    wpfactory · customer email verification for woocommerceFeb 15, 2025

  • Wishlist for WooCommerce: Multi Wishlists Per Customer <= 3.1.7 - Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name

    MediumCVSS 6.5No exploitEPSS 0%

    wpfactory · wishlist for woocommerceMar 7, 2025

  • includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple

    MediumCVSS 6.1No exploitEPSS 1%

    wpfactory · download plugins and themes from dashboardOct 7, 2019

  • Wishlist for WooCommerce: Multi Wishlists Per Customer PRO 3.0.8 - 3.1.2 - Reflected Cross-Site Scripting via wtab Parameter

    MediumCVSS 6.1No exploitEPSS 1%

    wpfactory · wishlist for woocommerceNov 23, 2024

  • CVE-2024-9377
    24Monitor

    Products, Order & Customers Export for WooCommerce <= 2.0.15 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    wpfactory · products\, order \& customers export for woocommerceOct 9, 2024

  • CVE-2024-8788
    24Monitor

    EU/UK VAT Manager for WooCommerce <= 2.12.12 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    wpfactory · eu\/uk vat manager for woocommerceSep 27, 2024

  • WordPress Products, Order & Customers Export for WooCommerce Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    wpfactory · products\, order \& customers export for woocommerceNov 14, 2023

  • CVE-2024-8656
    24Monitor

    WPFactory Helper <= 1.7.0 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    wpfactory · wpfactory helperSep 13, 2024

  • WordPress WPFactory Helper Plugin <= 1.5.2 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    wpfactory · wpfactory helperAug 5, 2023

  • CVE-2024-0821
    24Monitor

    Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce <= 3.2.8 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    wpfactory · cost of goods for woocommerceFeb 28, 2024

  • CVE-2024-9384
    24Monitor

    Quantity Dynamic Pricing & Bulk Discounts for WooCommerce <= 3.8.0 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    wpfactory · quantity dynamic pricing \& bulk discounts for woocommerceOct 4, 2024

  • CVE-2024-9205
    24Monitor

    Maximum Products per User for WooCommerce <= 4.2.8 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    wpfactory · maximum products per user for woocommerceOct 9, 2024

  • WordPress EU/UK VAT Manager for WooCommerce plugin <= 2.12.14 - CSRF to Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    wpfactory · eu\/uk vat manager for woocommerceOct 20, 2024

  • CVE-2023-0062
    21Monitor

    EAN for WooCommerce < 4.4.3 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    wpfactory · ean for woocommerceFeb 6, 2023

  • CVE-2024-9189
    21Monitor

    EU/UK VAT Manager for WooCommerce <= 2.12.12 - Missing Authorization

    MediumCVSS 5.3No exploitEPSS 0%

    wpfactory · eu\/uk vat manager for woocommerceSep 27, 2024

  • WordPress Back Button Widget Plugin <= 1.6.3 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    wpfactory · back button widgetDec 29, 2023

  • CVE-2023-6892
    21Monitor

    EAN for WooCommerce <= 4.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via alg_wc_ean_product_meta Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    wpfactory · ean for woocommerceApr 18, 2024

  • WordPress Change Add to Cart Button Text for WooCommerce plugin <= 2.2.2 - Cross Site Scripting (XSS) Vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    wpfactory · change add to cart button text for woocommerceMay 19, 2025

  • WordPress Back Button Widget plugin <= 1.6.8 - Cross Site Scripting (XSS) Vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    wpfactory · back button widgetMay 19, 2025