Extension WordPress
Vulnérabilités Checkout Mestres do WP for WooCommerce
Cette page rassemble les failles publiées pour Checkout Mestres do WP for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Checkout Mestres do WP for WooCommerce
5 fiches
Checkout Mestres do WP for WooCommerce 8.6.5 – 8.7.5 – Unauthenticated Arbitrary Options Update
The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5.…
8.6.5-8.7.5
Non indiqué
28/03/2025
Checkout Mestres WP <= 8.6 – Authenticated (Admin+) Local File Inclusion
The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6. This makes it possible for authenticated attackers, with Administrator-level access and above, to include…
*-8.6
8.6.1
24/09/2024
Checkout Mestres WP <= 7.1.9.6 – Unauthenticated SQL Injection
The Checkout Mestres WP plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, and including, 7.1.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-7.1.9.6
7.1.9.8
27/12/2023
Checkout Mestres WP <= 7.1.9.6 – Missing Authorization to Unauthenticated Arbitrary Options Update
The Checkout Mestres WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.1.9.6. This makes it possible for unauthenticated attackers to update…
*-7.1.9.6
7.1.9.8
27/12/2023
Checkout Mestres WP <= 7.1.9.6 – Authentication Bypass via Password Reset
The Checkout Mestres WP plugin for WordPress is vulnerable to authentication due to a weak password reset functionality in all versions up to, and including, 7.1.9.6. This makes it possible for unauthenticated attackers to reset the password of…
*-7.1.9.6
7.1.9.8
27/12/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.