CVE-2026-15648
- EPSS 0.19%
- Veröffentlicht 24.07.2026 06:52:00
- Zuletzt bearbeitet 24.07.2026 23:16:49
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possibl...
CVE-2026-15646
- EPSS 0.33%
- Veröffentlicht 23.07.2026 08:34:40
- Zuletzt bearbeitet 23.07.2026 16:17:14
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possibl...
CVE-2026-15647
- EPSS 0.31%
- Veröffentlicht 23.07.2026 08:34:40
- Zuletzt bearbeitet 23.07.2026 16:17:14
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it ...
CVE-2025-68519
- EPSS 0.23%
- Veröffentlicht 24.12.2025 12:31:22
- Zuletzt bearbeitet 27.04.2026 19:16:27
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Blind SQL Injection.This issue affects Brands for WooCommerce: from n/a through <= 3.8...
CVE-2023-44149
- EPSS 0.49%
- Veröffentlicht 13.12.2024 15:15:26
- Zuletzt bearbeitet 29.04.2026 10:16:16
Missing Authorization vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brands for WooCommerce: from n/a through <= 3.8.2.2.
CVE-2023-23667
- EPSS 0.36%
- Veröffentlicht 18.05.2023 11:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:37
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions.