Extension WordPress
Vulnérabilités Orders Tracking for WooCommerce
Cette page rassemble les failles publiées pour Orders Tracking for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Orders Tracking for WooCommerce
3 fiches
Orders Tracking for WooCommerce <= 1.2.10 – Unauthenticated Arbitrary Shortcode Execution
The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that…
*-1.2.10
1.2.11
09/05/2024
Orders Tracking for WooCommerce <= 1.2.5 – Authenticated (Administrator+) Directory Traversal via 'file_url'
The Orders Tracking for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.2.5 via the 'file_url' parameter when importing CSV files. This allows authenticated attackers, with administrator-level (manage_woocommerce) privileges and above,…
*-1.2.5
1.2.6
14/08/2023
Orders Tracking for WooCommerce <= 1.0.14 – Reflected Cross-Site Scripting
The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
*-1.0.14
1.1.10
27/12/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.