Extension WordPress

Vulnérabilités TrustMate.io – WooCommerce integration

Cette page rassemble les failles publiées pour TrustMate.io – WooCommerce integration, leurs plages de versions affectées et les correctifs signalés dans la base locale.

3Vulnérabilités
0Critiques
2Avec correctif
6,3CVSS maximal

Historique de sécurité

CVE et vulnérabilités de TrustMate.io – WooCommerce integration

3 fiches

CVE-2025-58802 Moyenne · 4,3
TrustMate.io – WooCommerce integration

TrustMate.io – WooCommerce integration <= 1.14.0 – Cross-Site Request Forgery

The TrustMate.io – WooCommerce integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.14.0. This is due to missing or incorrect nonce validation on a function. This makes it possible…

Versions affectées

*-1.14.0

Correctif

Non indiqué

Publication

05/09/2025

Vulnérabilité Moyenne · 6,3
TrustMate.io – WooCommerce integration

TrustMate.io integration for WooCommerce < 1.8.12 – Authenticated (Subscriber+) Arbitrary Blog Option Update

The TrustMate.io integration for WooCommerce plugin for WordPress is vulnerable to Blog Option Update via the 'save_checkbox' AJAX action in versions up to, and including, 1.8.12. This makes it possible for authenticated Subscriber+ attackers to update the vulnerable…

Versions affectées

*-1.8.11

Correctif

1.8.12

Publication

03/01/2022

Vulnérabilité Moyenne · 6,3
TrustMate.io – WooCommerce integration

TrustMate.io integration for WooCommerce < 1.8.12 – Authenticated (Subscriber+) Arbitrary Settings Update

The TrustMate.io integration for WooCommerce plugin for WordPress is vulnerable to Arbitrary Settings Update via the 'save_checkbox' AJAX action in versions up to, and including, 1.8.11. This makes it possible for authenticated Subscriber+ attackers to update otherwise restricted…

Versions affectées

*-1.8.11

Correctif

1.8.12

Publication

03/01/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités