Extension WordPress

Vulnérabilités Booster Plus for WooCommerce

Cette page rassemble les failles publiées pour Booster Plus for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
0Critiques
10Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Booster Plus for WooCommerce

10 fiches

CVE-2022-4017 Moyenne · 5,4
Booster Plus for WooCommerce

Booster (<= 6.0.0), Booster Plus (<= 6.0.0), and Booster Elite (<= 6.0.0) for WooCommerce – Cross-Site Request Forgery

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.0 (Booster), 6.0.0 (Plus), and 6.0.0 (Elite). This is due to missing or incorrect nonce…

Versions affectées

*-6.0.0

Correctif

6.0.1

Publication

02/01/2023

CVE-2022-4227 Moyenne · 6,1
Booster Plus for WooCommerce

Booster (<= 5.6.2), Booster Plus (< 6.0.0), and Booster Elite (< 6.0.0) for WooCommerce – Reflected Cross-Site Scripting

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.2 (Booster), as well as versions below 6.0.0 (Plus and Elite). This is due to…

Versions affectées

[*, 6.0.0)

Correctif

6.0.0

Publication

05/12/2022

CVE-2022-4016 Moyenne · 5,4
Booster Plus for WooCommerce

Booster (<= 5.6.6), Booster Plus (<= 5.6.5), and Booster Elite (<= 1.1.7) for WooCommerce – Cross-Site Request Forgery leading to Arbitrary Custom Role Creation/Deletion

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Booster), 5.6.5 (Plus), and 1.1.7 (Elite). This is due to missing or incorrect nonce…

Versions affectées

*-5.6.5

Correctif

5.6.6

Publication

21/11/2022

CVE-2022-3763 Élevée · 8,8
Booster Plus for WooCommerce

Booster for WooCommerce (Free <= 5.6.6, Premium <= 5.6.4) – Cross-Site Request Forgery to File Deletion

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Free) and 5.6.4 (Premium). This is due to missing or incorrect nonce validation when deleting files uploaded during…

Versions affectées

*-5.6.4

Correctif

5.6.5

Publication

31/10/2022

CVE-2022-3762 Moyenne · 6,5
Booster Plus for WooCommerce

Booster (<= 5.6.6) and Booster Plus (<= 5.6.4) for WooCommerce – Authenticated (Shop Manager+) Information Exposure via Arbitrary File Download

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file downloads due to missing sanitization and filename validation of a user-supplied parameter in versions up to, and including, 5.6.6 (5.6.4 for Booster Plus). This makes it…

Versions affectées

*-5.6.4

Correctif

5.6.5

Publication

27/10/2022

Vulnérabilité Moyenne · 6,5
Booster Plus for WooCommerce

Booster for WooCommerce (Free <= 5.6.2 and Premium <= 5.6.0) – Authenticated (Subscriber+) Order Modification

The Booster for WooCommerce plugin for WordPress is vulnerable to order modification due to a missing capability/authorization check in versions up to, and including, 5.6.2 (free) or 5.6.0 (premium). This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-5.6.0

Correctif

5.6.1

Publication

19/09/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités