Extension WordPress

Vulnérabilités ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution

Cette page rassemble les failles publiées pour ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
0Critiques
4Avec correctif
5,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution

4 fiches

CVE-2025-12358 Moyenne · 4,3
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution

ShopEngine <= 4.8.5 – Cross-Site Request Forgery to Wishlist Manipulation

The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an…

Versions affectées

*-4.8.5

Correctif

4.8.6

Publication

03/12/2025

CVE-2025-11888 Faible · 2,7
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 – Incorrect Authorization to Authenticated (Editor+) License Status Update

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions…

Versions affectées

*-4.8.4

Correctif

4.8.5

Publication

24/10/2025

CVE-2025-10173 Faible · 2,7
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.3 – Insufficient Authorization to Authenticated (Editor+) Settings Update

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3.…

Versions affectées

*-4.8.3

Correctif

4.8.4

Publication

25/09/2025

CVE-2022-45371 Moyenne · 5,4
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution

ShopEngine <= 4.1.1 – Cross-Site Request Forgery via get_product

The ShopEngine plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.1. This is due to missing or incorrect nonce validation on the get_product function. This makes it possible for unauthenticated attackers…

Versions affectées

*-4.1.1

Correctif

4.1.2

Publication

19/04/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités