Extension WordPress
Vulnérabilités WooCommerce Blocks
Cette page rassemble les failles publiées pour WooCommerce Blocks, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WooCommerce Blocks
4 fiches
WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image alt Attribute
The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a featured image 'alt' attribute in versions up to, and including, 8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-11.1.1
11.1.2
15/11/2023
WooCommerce Blocks < 5.5 – Authenticated Blind SQL Injection
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit…
*-2.5.15, 2.6-2.6.1, 2.7-2.7.1, 2.8, 2.9, 3.0, 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7-3.7.1, 3.8, 3.9, 4.0, 4.1, 4.2, 4.3, 4.4-4.4.2, 4.5-4.5.2, 4.6, 4.7, 4.8, 4.9-4.9.1, 5.0, 5.1, 5.2, 5.3-5.3.1, 5.4, 5.5
2.5.16, 2.6.2, 2.7.2, 2.8.1, 2.9.1, 3.0.1, 3.1.1, 3.2.1, 3.3.1, 3.4.1, 3.5.1, 3.6.1, 3.7.2, 3.8.1, 3.9.1, 4.0.1, 4.1.1, 4.2.1, 4.3.1, 4.4.3, 4.5.3, 4.6.1, 4.7.1, 4.8.1, 4.9.2, 5.0.1, 5.1.1, 5.2.1, 5.3.2, 5.4.1, 5.5.1
03/07/2021
WooCommerce Blocks <= 3.7.0 – Authorization Bypass
The WooCommerce Blocks plugins for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.7.0. This is due to insufficient validation on the account creation processes during checkout. This makes it possible for an unauthenticated…
[*, 3.7.1)
3.7.1
05/11/2020
WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 – Settings Bypass leading to Account Creation
The WooCommerce plugin for WordPress is vulnerable to unauthorized user account creation during checkout even when the “Allow customers to create an account during checkout” setting is disabled. was disabled due to missing authorization checks in versions up…
[*, 3.7.1)
3.7.1
05/11/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.