Extension WordPress
Vulnérabilités PayU CommercePro Plugin
Cette page rassemble les failles publiées pour PayU CommercePro Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de PayU CommercePro Plugin
3 fiches
PayU CommercePro Plugin <= 3.8.7 – Authentication Bypass
The PayU CommercePro Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.8.7. This is due to the plugin not properly verifying a user's identity through the update_cart_data() function. This makes…
*-3.8.7
3.8.8
05/06/2025
PayU CommercePro Plugin <= 3.8.3 – Unauthenticated Privilege Escalation
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost REST API endpoints not properly verifying a user's identity prior to…
*-3.8.3
3.8.4
06/01/2025
PayU India <= 3.8.8 – Reflected Cross-Site Scripting via type
The PayU India plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘type’ parameter in versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-3.8.8
3.8.9
26/02/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.