Extension WordPress
Vulnérabilités ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
Cette page rassemble les failles publiées pour ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
4 fiches
ShopEngine <= 4.8.5 – Cross-Site Request Forgery to Wishlist Manipulation
The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an…
*-4.8.5
4.8.6
03/12/2025
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 – Incorrect Authorization to Authenticated (Editor+) License Status Update
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions…
*-4.8.4
4.8.5
24/10/2025
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.3 – Insufficient Authorization to Authenticated (Editor+) Settings Update
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3.…
*-4.8.3
4.8.4
25/09/2025
ShopEngine <= 4.1.1 – Cross-Site Request Forgery via get_product
The ShopEngine plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.1. This is due to missing or incorrect nonce validation on the get_product function. This makes it possible for unauthenticated attackers…
*-4.1.1
4.1.2
19/04/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.