Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8
CVE-2023-0080
- EPSS 1.13%
- Veröffentlicht 13.02.2023 15:15:20
- Zuletzt bearbeitet 21.03.2025 16:15:15
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow t...
8.8
CVE-2022-38134
- EPSS 0.84%
- Veröffentlicht 23.09.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:15:51
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
8.8
CVE-2022-38470
- EPSS 0.32%
- Veröffentlicht 23.09.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:16:32
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
7.5
CVE-2022-40194
- EPSS 0.77%
- Veröffentlicht 23.09.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:21:02
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress