Woocommerce

Woocommerce

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 13.08%
  • Veröffentlicht 27.12.2020 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:23:44

The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

  • EPSS 0.13%
  • Veröffentlicht 19.06.2020 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:39:37

WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS) via includes/admin/importers/class-wc-product-csv-importer-controller.php.

  • EPSS 0.19%
  • Veröffentlicht 26.02.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:51:07

WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.

  • EPSS 1.39%
  • Veröffentlicht 15.01.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:02:00

The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a sh...

Exploit
  • EPSS 1.57%
  • Veröffentlicht 15.01.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:55

In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string t...

  • EPSS 0.24%
  • Veröffentlicht 08.02.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 02:27:13

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

  • EPSS 0.12%
  • Veröffentlicht 04.01.2017 02:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.