Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
5.3
CVE-2025-14073
- EPSS 0.23%
- Veröffentlicht 01.08.2026 09:16:57
- Zuletzt bearbeitet 29.09.2026 14:10:00
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()`...
8.2
CVE-2026-9284
- EPSS 0.4%
- Veröffentlicht 23.05.2026 04:27:17
- Zuletzt bearbeitet 23.07.2026 11:10:00
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to...
8.8
CVE-2023-35917
- EPSS 0.29%
- Veröffentlicht 22.06.2023 12:15:12
- Zuletzt bearbeitet 21.11.2024 08:08:58
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.
1