CVE-2026-93771
- EPSS 0.37%
- Veröffentlicht 30.09.2026 12:26:56
- Zuletzt bearbeitet 30.09.2026 14:17:36
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
CVE-2025-48240
- EPSS 0.25%
- Veröffentlicht 19.05.2025 14:44:53
- Zuletzt bearbeitet 23.04.2026 15:30:56
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Cost of Goods for WooCommerce cost-of-goods-for-woocommerce allows Stored XSS.This issue affects Cost of Goods for WooCommerce: from n/a t...
CVE-2023-23868
- EPSS 0.61%
- Veröffentlicht 09.12.2024 13:15:21
- Zuletzt bearbeitet 28.04.2026 19:19:31
Missing Authorization vulnerability in WPFactory Cost of Goods for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost of Goods for WooCommerce: from n/a through 2.8.6.
CVE-2024-0821
- EPSS 0.4%
- Veröffentlicht 29.02.2024 01:43:29
- Zuletzt bearbeitet 08.04.2026 19:19:17
The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'section' parameter in all versions up to, and including, 3.2.8 due to insufficient input sanitizatio...