CVE-2024-35777
- EPSS 0.35%
- Veröffentlicht 09.07.2024 10:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a through 8.9.2.
CVE-2024-1310
- EPSS 0.68%
- Veröffentlicht 15.04.2024 05:15:14
- Zuletzt bearbeitet 20.07.2026 19:07:37
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
CVE-2024-22155
- EPSS 0.23%
- Veröffentlicht 07.04.2024 18:15:08
- Zuletzt bearbeitet 28.04.2026 19:23:12
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2.
CVE-2023-47777
- EPSS 0.78%
- Veröffentlicht 30.11.2023 12:15:08
- Zuletzt bearbeitet 28.04.2026 19:22:00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: ...
CVE-2017-17058
- EPSS 23.67%
- Veröffentlicht 29.11.2017 07:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traver...