Cedcommerce

Wholesale Market

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 15.08.2026 06:38:10
  • Zuletzt bearbeitet 20.08.2026 12:48:10

The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce (which is ...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 16.05.2025 20:33:45
  • Zuletzt bearbeitet 12.06.2025 16:46:05

The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF att...

Exploit
  • EPSS 1.83%
  • Veröffentlicht 02.01.2023 22:15:16
  • Zuletzt bearbeitet 10.04.2025 19:15:52

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.