Wpfactory

Ean For Woocommerce

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 19.05.2025 14:44:56
  • Last modified 21.05.2025 20:25:33

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for WooCommerce allows Stored XSS. This issue affects EAN for WooCommerce: from n/a through 5.4.6.

  • EPSS 0.04%
  • Published 27.03.2025 14:15:49
  • Last modified 27.03.2025 16:45:12

Missing Authorization vulnerability in WPFactory EAN for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through 5.3.5.

  • EPSS 6.95%
  • Published 17.05.2024 09:15:43
  • Last modified 12.02.2025 15:42:09

Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.

  • EPSS 0.13%
  • Published 18.04.2024 11:15:37
  • Last modified 11.02.2025 20:27:49

The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on u...

  • EPSS 0.21%
  • Published 18.04.2024 11:15:37
  • Last modified 11.02.2025 20:31:53

The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes ...

Exploit
  • EPSS 0.29%
  • Published 06.02.2023 20:15:12
  • Last modified 25.03.2025 18:15:29

The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above t...