Extension WordPress
Vulnérabilités Wholesale Market for WooCommerce
Cette page rassemble les failles publiées pour Wholesale Market for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Wholesale Market for WooCommerce
4 fiches
Wholesale Market for WooCommerce < 2.0.0 – Authenticated (Administrator+) Arbitrary Log File Download
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to Arbitrary Log File Download in versions below 2.0.0. This due to the plugin not verifying that paths accessed belong to the site they are accessed from. This…
[*, 2.0.0)
2.0.0
12/12/2022
Wholesale Market for WooCommerce <= 2.0.0 & Wholesale Market <= 2.2.1 – Cross-Site Request Forgery
Multiple plugins for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing or incorrect nonce validation on the 'wholesale_market' page. This makes it possible for unauthenticated attackers to update the plugin's settings…
*-2.0.0
2.0.1
08/12/2022
Wholesale Market for WooCommerce <= 1.0.6 – Unauthenticated Arbitrary File Download
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing capability checks and user input validation during the system path generation process in versions up to, and including, 1.0.6. This makes…
*-1.0.6
1.0.7
28/11/2022
Wholesale Market for WooCommerce <= 1.0.7 – Authenticated (Administrator+) Arbitrary File Download
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing user input validation during the system path generation process in versions up to, and including, 1.0.7. This makes it possible for…
*-1.0.7
1.0.8
28/11/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.