İçeriğe atla
Noroxi

WooCommerce kayıtları

woocommerce üreticisine ait 72 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%68,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

72 kayıt
  • CVE-2021-24212
    41Planlayın

    WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE

    KritikCVSS 9,8Kavram kanıtıEPSS %8

    woocommerce · help scout5 Nis 2021

  • CVE-2023-35049
    39İzleyin

    WordPress WooCommerce Stripe Payment Gateway plugin <= 7.4.0 - Unauthenticated Broken Access Control vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    woocommerce · stripe payment gateway19 Haz 2024

  • CVE-2023-51494
    39İzleyin

    WordPress WooCommerce Product Vendors plugin <= 2.2.1 - Broken Access Control vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    woocommerce · product vendors9 Haz 2024

  • CVE-2020-35627
    36İzleyin

    Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute a

    YüksekCVSS 8,8İstismar yokEPSS %2

    woocommerce · gift cards28 Ara 2020

  • CVE-2017-18356
    36İzleyin

    In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user a

    YüksekCVSS 8,8İstismar yokEPSS %2

    woocommerce · woocommerce15 Oca 2019

  • CVE-2023-33318
    35İzleyin

    WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.40 is vulnerable to Arbitrary File Upload

    YüksekCVSS 8,8İstismar yokEPSS %1

    woocommerce · automatewoo20 Ara 2023

  • CVE-2019-20891
    35İzleyin

    WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross

    YüksekCVSS 8,8İstismar yokEPSS %1

    woocommerce · woocommerce19 Haz 2020

  • CVE-2024-24799
    35İzleyin

    WordPress WooCommerce Box Office plugin <= 1.2.2 - Broken Access Control vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    woocommerce · box office26 Mar 2024

  • CVE-2023-36514
    35İzleyin

    WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.5 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · shipping multiple addresses17 Tem 2023

  • CVE-2023-32794
    35İzleyin

    WordPress WooCommerce Product Add-ons Plugin <= 6.1.3 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · product addons9 Kas 2023

  • CVE-2023-32744
    35İzleyin

    WordPress WooCommerce Product Recommendations Plugin < 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · product recommendations9 Kas 2023

  • CVE-2023-32745
    35İzleyin

    WordPress AutomateWoo Plugin <= 5.7.1 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · automatewoo9 Kas 2023

  • CVE-2023-35917
    35İzleyin

    WordPress WooCommerce PayPal Payments Plugin <= 2.0.4 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · paypal payments22 Haz 2023

  • CVE-2023-52222
    35İzleyin

    WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · woocommerce8 Oca 2024

  • CVE-2023-35880
    35İzleyin

    WordPress WooCommerce Brands Plugin <= 1.6.49 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · brands17 Tem 2023

  • CVE-2023-36511
    35İzleyin

    WordPress WooCommerce Order Barcodes Plugin <= 1.6.4 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · woocommerce order barcodes17 Tem 2023

  • CVE-2023-33316
    35İzleyin

    WordPress WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · automatewoo28 May 2023

  • CVE-2023-36513
    35İzleyin

    WordPress AutomateWoo Plugin <= 5.7.5 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · automatewoo17 Tem 2023

  • CVE-2023-44999
    35İzleyin

    WordPress WooCommerce Stripe Gateway plugin <= 7.6.0 - Cross Site Request Forgery (CSRF) vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    woocommerce · stripe payment gateway27 Mar 2024

  • CVE-2018-20714
    33İzleyin

    The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability.

    YüksekCVSS 8,1İstismar yokEPSS %2

    woocommerce · woocommerce15 Oca 2019

  • CVE-2023-33330
    32İzleyin

    WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.50 is vulnerable to SQL Injection

    YüksekCVSS 8,1İstismar yokEPSS %1

    woocommerce · automatewoo20 Ara 2023

  • CVE-2023-49817
    32İzleyin

    WordPress Flexible Woocommerce Checkout Field Editor plugin <= 2.0.1 - Broken Access Control vulnerability

    YüksekCVSS 8,2İstismar yokEPSS %1

    heolixfy · flexible woocommerce checkout field editor9 Ara 2024

  • CVE-2023-34000
    30İzleyin

    WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.4.0 is vulnerable to Insecure Direct Object References (IDOR)

    YüksekCVSS 7,5İstismar yokEPSS %1

    woocommerce · stripe payment gateway14 Haz 2023

  • CVE-2020-11497
    30İzleyin

    An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress.

    YüksekCVSS 7,5İstismar yokEPSS %1

    woocommerce · nab transact26 Ağu 2020

  • CVE-2024-10567
    30İzleyin

    TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access

    YüksekCVSS 7,5İstismar yokEPSS %0

    templateinvaders · ti woocommerce wishlist4 Ara 2024