Extension WordPress
Vulnérabilités Admin and Customer Messages After Order for WooCommerce: OrderConvo
Cette page rassemble les failles publiées pour Admin and Customer Messages After Order for WooCommerce: OrderConvo, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Admin and Customer Messages After Order for WooCommerce: OrderConvo
5 fiches
Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 – Missing Authorization to Unauthenticated Information Disclosure
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `get_order_by_id()` function in all versions up to, and including, 14.…
*-14
15
24/11/2025
Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 – Missing Authorization to Unauthenticated User Impersonation in Order Messages
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14. This is due to a flawed permission check in the REST API…
*-14
15
24/11/2025
Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 13.5 – Unauthenticated Arbitrary File Read
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 13.5 via the '/wp-json/wooconvo/v1/download-file' REST API. This makes it possible for unauthenticated attackers…
*-13.5
14
16/09/2025
Admin and Customer Messages After Order for WooCommerce <= 13.2 – Authenticated (Subscriber+) Limited File Upload to Cross-Site Scripting
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This…
*-13.2
13.3
15/01/2025
OrderConvo <= 12.4 – Missing Authorization to Arbitrary File Upload
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on a REST API endpoint in all versions up to, and including, 12.4.…
*-12.4
12.5
25/04/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.