Extension WordPress

Vulnérabilités WholesaleX – B2B & Wholesale Plugin for WooCommerce with Wholesale Prices

Cette page rassemble les failles publiées pour WholesaleX – B2B & Wholesale Plugin for WooCommerce with Wholesale Prices, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
1Critiques
4Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WholesaleX – B2B & Wholesale Plugin for WooCommerce with Wholesale Prices

4 fiches

CVE-2024-30542 Moyenne · 6,5
WholesaleX – B2B & Wholesale Plugin for WooCommerce with Wholesale Prices

WholesaleX <= 1.3.2 – Unauthenticated Privilege Escalation

The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.3.2. This makes it possible for unauthenticated attackers to escalate their…

Versions affectées

*-1.3.2

Correctif

1.3.3

Publication

29/03/2024

CVE-2024-30224 Critique · 9,8
WholesaleX – B2B & Wholesale Plugin for WooCommerce with Wholesale Prices

WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) <= 1.3.2 – Unauthenticated PHP Object Injection

The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.2 via deserialization of untrusted input. This makes it possible…

Versions affectées

*-1.3.2

Correctif

1.3.3

Publication

26/03/2024

CVE-2024-30233 Moyenne · 4,3
WholesaleX – B2B & Wholesale Plugin for WooCommerce with Wholesale Prices

WholesaleX <= 1.3.1 – Sensitive Information Exposure via export_users

The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the 'export_users'. This makes it possible for authenticated…

Versions affectées

*-1.3.1

Correctif

1.3.2

Publication

26/03/2024

CVE-2024-30234 Moyenne · 4,3
WholesaleX – B2B & Wholesale Plugin for WooCommerce with Wholesale Prices

WholesaleX <= 1.3.1 – Authenticated(Subscriber+) Missing Authorization via multiple AJAX actions

The WholesaleX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wc_install_callback AJAX function in versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.3.1

Correctif

1.3.2

Publication

26/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités