CVE-2026-66707
- EPSS 0.16%
- Veröffentlicht 06.08.2026 14:28:08
- Zuletzt bearbeitet 12.08.2026 20:58:37
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
CVE-2026-49059
- EPSS 0.23%
- Veröffentlicht 27.05.2026 15:16:33
- Zuletzt bearbeitet 27.05.2026 19:43:00
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.
CVE-2025-64296
- EPSS 0.2%
- Veröffentlicht 29.10.2025 04:16:05
- Zuletzt bearbeitet 23.04.2026 15:35:11
Missing Authorization vulnerability in Facebook Facebook for WooCommerce facebook-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Facebook for WooCommerce: from n/a through <= 3.5.7.
CVE-2019-15840
- EPSS 0.69%
- Veröffentlicht 30.08.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:35
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
CVE-2019-15841
- EPSS 0.69%
- Veröffentlicht 30.08.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:35
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.