Extension WordPress
Vulnérabilités Customer Email Verification for WooCommerce
Cette page rassemble les failles publiées pour Customer Email Verification for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Customer Email Verification for WooCommerce
5 fiches
Customer Email Verification for WooCommerce <= 2.9.4 – Authenticated (Contributor+) Sensitive Information Exposure
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
*-2.9.4
2.9.5
14/02/2025
Customer Email Verification for WooCommerce <= 2.9.5 – Authentication Bypass via Shortcode
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with…
*-2.9.5
2.9.6
11/02/2025
Email Verification for WooCommerce <= 2.8.10 – Unauthenticated SQL Injection
The Email Verification for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
*-2.8.10
2.9.0
15/10/2024
Customer Email Verification for WooCommerce <= 2.7.4 – Email Verification and Authentication Bypass due to Insufficient Randomness
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for…
*-2.7.4
2.7.5
29/04/2024
Email Verification for WooCommerce <= 1.8.1 – Authentication Bypass
The Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass due to insufficient validation on the alg_wc_ev_activation_code value found in the verify() function which makes it possible for users to spoof email validation for any…
*-1.8.1
1.8.2
14/07/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.