CVE-2023-6979
- EPSS 1.15%
- Veröffentlicht 11.01.2024 09:15:53
- Zuletzt bearbeitet 08.04.2026 18:18:46
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for ...
CVE-2023-0080
- EPSS 1.13%
- Veröffentlicht 13.02.2023 15:15:20
- Zuletzt bearbeitet 21.03.2025 16:15:15
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow t...
CVE-2022-38134
- EPSS 0.84%
- Veröffentlicht 23.09.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:15:51
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
CVE-2022-38470
- EPSS 0.32%
- Veröffentlicht 23.09.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:16:32
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
CVE-2022-40194
- EPSS 0.77%
- Veröffentlicht 23.09.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:21:02
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress