CVE-2025-48249
- EPSS 0.06%
- Veröffentlicht 19.05.2025 14:44:56
- Zuletzt bearbeitet 21.05.2025 20:25:33
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for WooCommerce allows Stored XSS. This issue affects EAN for WooCommerce: from n/a through 5.4.6.
CVE-2025-22673
- EPSS 0.04%
- Veröffentlicht 27.03.2025 14:15:49
- Zuletzt bearbeitet 27.03.2025 16:45:12
Missing Authorization vulnerability in WPFactory EAN for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through 5.3.5.
CVE-2024-34370
- EPSS 6.95%
- Veröffentlicht 17.05.2024 09:15:43
- Zuletzt bearbeitet 12.02.2025 15:42:09
Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.
CVE-2023-6892
- EPSS 0.13%
- Veröffentlicht 18.04.2024 11:15:37
- Zuletzt bearbeitet 11.02.2025 20:27:49
The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on u...
CVE-2023-6897
- EPSS 0.21%
- Veröffentlicht 18.04.2024 11:15:37
- Zuletzt bearbeitet 11.02.2025 20:31:53
The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes ...
CVE-2023-0062
- EPSS 0.29%
- Veröffentlicht 06.02.2023 20:15:12
- Zuletzt bearbeitet 25.03.2025 18:15:29
The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above t...