WooCommerce kayıtları
woocommerce üreticisine ait 72 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %68,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-352 Cross-Site Request Forgery (CSRF)14
- CWE-862 Missing Authorization11
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')5
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
72 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2021-24212Kavram kanıtı | WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCEwoocommerce · help scout · CWE-434 | Kritik9,8 | — | %7,9 | 5 Nis 2021 |
39İzleyin | CVE-2023-35049İstismar yok | WordPress WooCommerce Stripe Payment Gateway plugin <= 7.4.0 - Unauthenticated Broken Access Control vulnerabilitywoocommerce · stripe payment gateway · CWE-862 | Kritik9,8 | — | %0,6 | 19 Haz 2024 |
39İzleyin | CVE-2023-51494İstismar yok | WordPress WooCommerce Product Vendors plugin <= 2.2.1 - Broken Access Control vulnerabilitywoocommerce · product vendors · CWE-862 | Kritik9,8 | — | %0,4 | 9 Haz 2024 |
36İzleyin | CVE-2020-35627İstismar yok | Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute awoocommerce · gift cards · CWE-434 | Yüksek8,8 | — | %2,1 | 28 Ara 2020 |
36İzleyin | CVE-2017-18356İstismar yok | In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user awoocommerce · woocommerce · CWE-94 | Yüksek8,8 | — | %2,0 | 15 Oca 2019 |
35İzleyin | CVE-2023-33318İstismar yok | WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.40 is vulnerable to Arbitrary File Uploadwoocommerce · automatewoo · CWE-434 | Yüksek8,8 | — | %0,8 | 20 Ara 2023 |
35İzleyin | CVE-2019-20891İstismar yok | WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored crosswoocommerce · woocommerce · CWE-352 | Yüksek8,8 | — | %0,5 | 19 Haz 2020 |
35İzleyin | CVE-2024-24799İstismar yok | WordPress WooCommerce Box Office plugin <= 1.2.2 - Broken Access Control vulnerabilitywoocommerce · box office · CWE-862 | Yüksek8,8 | — | %0,5 | 26 Mar 2024 |
35İzleyin | CVE-2023-36514İstismar yok | WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.5 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · shipping multiple addresses · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Tem 2023 |
35İzleyin | CVE-2023-32794İstismar yok | WordPress WooCommerce Product Add-ons Plugin <= 6.1.3 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · product addons · CWE-352 | Yüksek8,8 | — | %0,3 | 9 Kas 2023 |
35İzleyin | CVE-2023-32744İstismar yok | WordPress WooCommerce Product Recommendations Plugin < 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · product recommendations · CWE-352 | Yüksek8,8 | — | %0,3 | 9 Kas 2023 |
35İzleyin | CVE-2023-32745İstismar yok | WordPress AutomateWoo Plugin <= 5.7.1 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · automatewoo · CWE-352 | Yüksek8,8 | — | %0,3 | 9 Kas 2023 |
35İzleyin | CVE-2023-35917İstismar yok | WordPress WooCommerce PayPal Payments Plugin <= 2.0.4 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · paypal payments · CWE-352 | Yüksek8,8 | — | %0,3 | 22 Haz 2023 |
35İzleyin | CVE-2023-52222İstismar yok | WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · woocommerce · CWE-352 | Yüksek8,8 | — | %0,3 | 8 Oca 2024 |
35İzleyin | CVE-2023-35880İstismar yok | WordPress WooCommerce Brands Plugin <= 1.6.49 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · brands · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Tem 2023 |
35İzleyin | CVE-2023-36511İstismar yok | WordPress WooCommerce Order Barcodes Plugin <= 1.6.4 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · woocommerce order barcodes · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Tem 2023 |
35İzleyin | CVE-2023-33316İstismar yok | WordPress WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · automatewoo · CWE-352 | Yüksek8,8 | — | %0,2 | 28 May 2023 |
35İzleyin | CVE-2023-36513İstismar yok | WordPress AutomateWoo Plugin <= 5.7.5 is vulnerable to Cross Site Request Forgery (CSRF)woocommerce · automatewoo · CWE-352 | Yüksek8,8 | — | %0,2 | 17 Tem 2023 |
35İzleyin | CVE-2023-44999İstismar yok | WordPress WooCommerce Stripe Gateway plugin <= 7.6.0 - Cross Site Request Forgery (CSRF) vulnerabilitywoocommerce · stripe payment gateway · CWE-352 | Yüksek8,8 | — | %0,2 | 27 Mar 2024 |
33İzleyin | CVE-2018-20714İstismar yok | The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability.woocommerce · woocommerce · CWE-22 | Yüksek8,1 | — | %1,8 | 15 Oca 2019 |
32İzleyin | CVE-2023-33330İstismar yok | WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.50 is vulnerable to SQL Injectionwoocommerce · automatewoo · CWE-89 | Yüksek8,1 | — | %0,6 | 20 Ara 2023 |
32İzleyin | CVE-2023-49817İstismar yok | WordPress Flexible Woocommerce Checkout Field Editor plugin <= 2.0.1 - Broken Access Control vulnerabilityheolixfy · flexible woocommerce checkout field editor · CWE-862 | Yüksek8,2 | — | %0,6 | 9 Ara 2024 |
30İzleyin | CVE-2023-34000İstismar yok | WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.4.0 is vulnerable to Insecure Direct Object References (IDOR)woocommerce · stripe payment gateway · CWE-639 | Yüksek7,5 | — | %1,2 | 14 Haz 2023 |
30İzleyin | CVE-2020-11497İstismar yok | An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress.woocommerce · nab transact · CWE-354 | Yüksek7,5 | — | %1,2 | 26 Ağu 2020 |
30İzleyin | CVE-2024-10567İstismar yok | TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Accesstemplateinvaders · ti woocommerce wishlist · CWE-862 | Yüksek7,5 | — | %0,4 | 4 Ara 2024 |
- CVE-2021-2421241Planlayın
WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE
KritikCVSS 9,8Kavram kanıtıEPSS %8woocommerce · help scout5 Nis 2021
- CVE-2023-3504939İzleyin
WordPress WooCommerce Stripe Payment Gateway plugin <= 7.4.0 - Unauthenticated Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %1woocommerce · stripe payment gateway19 Haz 2024
- CVE-2023-5149439İzleyin
WordPress WooCommerce Product Vendors plugin <= 2.2.1 - Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %0woocommerce · product vendors9 Haz 2024
- CVE-2020-3562736İzleyin
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute a
YüksekCVSS 8,8İstismar yokEPSS %2woocommerce · gift cards28 Ara 2020
- CVE-2017-1835636İzleyin
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user a
YüksekCVSS 8,8İstismar yokEPSS %2woocommerce · woocommerce15 Oca 2019
- CVE-2023-3331835İzleyin
WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.40 is vulnerable to Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %1woocommerce · automatewoo20 Ara 2023
- CVE-2019-2089135İzleyin
WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross
YüksekCVSS 8,8İstismar yokEPSS %1woocommerce · woocommerce19 Haz 2020
- CVE-2024-2479935İzleyin
WordPress WooCommerce Box Office plugin <= 1.2.2 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1woocommerce · box office26 Mar 2024
- CVE-2023-3651435İzleyin
WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.5 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · shipping multiple addresses17 Tem 2023
- CVE-2023-3279435İzleyin
WordPress WooCommerce Product Add-ons Plugin <= 6.1.3 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · product addons9 Kas 2023
- CVE-2023-3274435İzleyin
WordPress WooCommerce Product Recommendations Plugin < 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · product recommendations9 Kas 2023
- CVE-2023-3274535İzleyin
WordPress AutomateWoo Plugin <= 5.7.1 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · automatewoo9 Kas 2023
- CVE-2023-3591735İzleyin
WordPress WooCommerce PayPal Payments Plugin <= 2.0.4 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · paypal payments22 Haz 2023
- CVE-2023-5222235İzleyin
WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · woocommerce8 Oca 2024
- CVE-2023-3588035İzleyin
WordPress WooCommerce Brands Plugin <= 1.6.49 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · brands17 Tem 2023
- CVE-2023-3651135İzleyin
WordPress WooCommerce Order Barcodes Plugin <= 1.6.4 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · woocommerce order barcodes17 Tem 2023
- CVE-2023-3331635İzleyin
WordPress WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · automatewoo28 May 2023
- CVE-2023-3651335İzleyin
WordPress AutomateWoo Plugin <= 5.7.5 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · automatewoo17 Tem 2023
- CVE-2023-4499935İzleyin
WordPress WooCommerce Stripe Gateway plugin <= 7.6.0 - Cross Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0woocommerce · stripe payment gateway27 Mar 2024
- CVE-2018-2071433İzleyin
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability.
YüksekCVSS 8,1İstismar yokEPSS %2woocommerce · woocommerce15 Oca 2019
- CVE-2023-3333032İzleyin
WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.50 is vulnerable to SQL Injection
YüksekCVSS 8,1İstismar yokEPSS %1woocommerce · automatewoo20 Ara 2023
- CVE-2023-4981732İzleyin
WordPress Flexible Woocommerce Checkout Field Editor plugin <= 2.0.1 - Broken Access Control vulnerability
YüksekCVSS 8,2İstismar yokEPSS %1heolixfy · flexible woocommerce checkout field editor9 Ara 2024
- CVE-2023-3400030İzleyin
WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.4.0 is vulnerable to Insecure Direct Object References (IDOR)
YüksekCVSS 7,5İstismar yokEPSS %1woocommerce · stripe payment gateway14 Haz 2023
- CVE-2020-1149730İzleyin
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress.
YüksekCVSS 7,5İstismar yokEPSS %1woocommerce · nab transact26 Ağu 2020
- CVE-2024-1056730İzleyin
TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access
YüksekCVSS 7,5İstismar yokEPSS %0templateinvaders · ti woocommerce wishlist4 Ara 2024