Extension WordPress
Vulnérabilités Waitlist Woocommerce ( Back in stock notifier )
Cette page rassemble les failles publiées pour Waitlist Woocommerce ( Back in stock notifier ), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Waitlist Woocommerce ( Back in stock notifier )
5 fiches
Waitlist Woocommerce ( Back in stock notifier ) <= 2.7.5 – Reflected Cross-Site Scripting
The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.5.…
*-2.7.5
2.7.6
13/09/2024
Waitlist Woocommerce ( Back in stock notifier ) <= 2.6 – Missing Authorization
The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the send_email() and remove_row() function in versions up to, and including, 2.6. This makes…
*-2.6
2.6.1
07/08/2024
XootiX Framework <= Various Plugin Versions – Missing Authorization to Arbitrary Options Update
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access…
*-2.6
2.6.1
05/06/2024
Waitlist Woocommerce ( Back in stock notifier ) <= 2.5.2 – Cross-Site Request Forgery to Settings Reset
The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. This is due to missing nonce validation on the reset_settings() function. This makes…
*-2.5.2
2.5.3
27/06/2023
Waitlist Woocommerce ( Back in stock notifier ) <= 2.5.1 – Cross-Site Request Forgery to Arbitrary Options Update
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it…
*-2.5.1
2.5.2
13/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.