Gravitymaster

Product Enquiry For Woocommerce

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 13.07.2024 06:15:03
  • Zuletzt bearbeitet 13.05.2025 13:48:26

The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html cap...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 22.01.2024 20:15:47
  • Zuletzt bearbeitet 20.06.2025 19:15:28

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack

Exploit
  • EPSS 0.07%
  • Veröffentlicht 22.01.2024 20:15:47
  • Zuletzt bearbeitet 30.05.2025 15:15:28

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capab...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 16.01.2024 16:15:14
  • Zuletzt bearbeitet 27.02.2026 21:48:17

The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users su...

  • EPSS 0.06%
  • Veröffentlicht 18.12.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 08:33:47

Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0.

  • EPSS 0.1%
  • Veröffentlicht 16.11.2023 19:15:09
  • Zuletzt bearbeitet 27.02.2026 21:48:07

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.

  • EPSS 0.1%
  • Veröffentlicht 13.11.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:30:41

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.