Extension WordPress
Vulnérabilités Booster Plus for WooCommerce
Cette page rassemble les failles publiées pour Booster Plus for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Booster Plus for WooCommerce
10 fiches
Booster Plus for WooCommerce <= 7.2.4 – Reflected Cross-Site Scripting
The Booster Plus for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-7.2.4
7.2.5
17/04/2025
Booster Plus for WooCommerce < 7.1.2 – Missing Authorization to Arbitrary Page/Post Deletion
The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on an unknown function in all versions up to 7.1.2 (exclusive). This makes it possible for authenticated…
[*, 7.1.2)
7.1.2
05/01/2024
Booster Plus for WooCommerce < 7.1.3 – Missing Authorization to Arbitrary Options Disclosure
The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on an unknown function in all versions up to 7.1.3 (exclusive). This makes it possible for authenticated…
[*, 7.1.3)
7.1.3
05/01/2024
Booster Plus for WooCommerce < 7.1.2 – Missing Authorization to Order Information Disclosure
The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on an unknown function in all versions up to 7.1.2 (exclusive). This makes it possible for authenticated…
[*, 7.1.2)
7.1.2
05/01/2024
Booster (<= 6.0.0), Booster Plus (<= 6.0.0), and Booster Elite (<= 6.0.0) for WooCommerce – Cross-Site Request Forgery
The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.0 (Booster), 6.0.0 (Plus), and 6.0.0 (Elite). This is due to missing or incorrect nonce…
*-6.0.0
6.0.1
02/01/2023
Booster (<= 5.6.2), Booster Plus (< 6.0.0), and Booster Elite (< 6.0.0) for WooCommerce – Reflected Cross-Site Scripting
The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.2 (Booster), as well as versions below 6.0.0 (Plus and Elite). This is due to…
[*, 6.0.0)
6.0.0
05/12/2022
Booster (<= 5.6.6), Booster Plus (<= 5.6.5), and Booster Elite (<= 1.1.7) for WooCommerce – Cross-Site Request Forgery leading to Arbitrary Custom Role Creation/Deletion
The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Booster), 5.6.5 (Plus), and 1.1.7 (Elite). This is due to missing or incorrect nonce…
*-5.6.5
5.6.6
21/11/2022
Booster for WooCommerce (Free <= 5.6.6, Premium <= 5.6.4) – Cross-Site Request Forgery to File Deletion
The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Free) and 5.6.4 (Premium). This is due to missing or incorrect nonce validation when deleting files uploaded during…
*-5.6.4
5.6.5
31/10/2022
Booster (<= 5.6.6) and Booster Plus (<= 5.6.4) for WooCommerce – Authenticated (Shop Manager+) Information Exposure via Arbitrary File Download
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file downloads due to missing sanitization and filename validation of a user-supplied parameter in versions up to, and including, 5.6.6 (5.6.4 for Booster Plus). This makes it…
*-5.6.4
5.6.5
27/10/2022
Booster for WooCommerce (Free <= 5.6.2 and Premium <= 5.6.0) – Authenticated (Subscriber+) Order Modification
The Booster for WooCommerce plugin for WordPress is vulnerable to order modification due to a missing capability/authorization check in versions up to, and including, 5.6.2 (free) or 5.6.0 (premium). This makes it possible for authenticated attackers, with subscriber-level…
*-5.6.0
5.6.1
19/09/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.