CVE-2025-48249
- EPSS 0.14%
- Veröffentlicht 19.05.2025 14:44:56
- Zuletzt bearbeitet 23.04.2026 15:30:57
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for WooCommerce ean-for-woocommerce allows Stored XSS.This issue affects EAN for WooCommerce: from n/a through <= 5.4.6.
CVE-2025-22673
- EPSS 0.23%
- Veröffentlicht 27.03.2025 14:15:49
- Zuletzt bearbeitet 23.04.2026 15:23:22
Missing Authorization vulnerability in WPFactory EAN for WooCommerce ean-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through <= 5.3.5.
CVE-2024-34370
- EPSS 9.15%
- Veröffentlicht 17.05.2024 09:15:43
- Zuletzt bearbeitet 12.02.2025 15:42:09
Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.
CVE-2023-6892
- EPSS 0.13%
- Veröffentlicht 18.04.2024 11:15:37
- Zuletzt bearbeitet 08.04.2026 19:19:01
The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on u...
CVE-2023-6897
- EPSS 0.21%
- Veröffentlicht 18.04.2024 11:15:37
- Zuletzt bearbeitet 08.04.2026 17:17:16
The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes ...
CVE-2023-0062
- EPSS 0.2%
- Veröffentlicht 06.02.2023 20:15:12
- Zuletzt bearbeitet 25.03.2025 18:15:29
The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above t...