Extension WordPress
Vulnérabilités BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net, page 2
Cette page rassemble les failles publiées pour BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
24 fiches
BEAR <= 1.1.3.3 – Cross-Site Request Forgery to Product Manipulation
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Missing Authorization to Product Manipulation
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher)…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Cross-Site Request Forgery to Product Manipulation
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated attackers to…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.1 – Cross-Site Request Forgery via Multiple Functions
The BEAR plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.1. This is due to missing or incorrect nonce validation on the woobe_create_new_product, woobe_duplicate_products, and woobe_delete_products functions. This makes it possible…
*-1.1.3.1
1.1.3.2
22/05/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.