Extension WordPress

Vulnérabilités Wallet for WooCommerce

Cette page rassemble les failles publiées pour Wallet for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
0Critiques
9Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Wallet for WooCommerce

9 fiches

CVE-2026-12103 Moyenne · 4,3
Wallet for WooCommerce

Wallet for WooCommerce <= 1.6.4 – Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action

The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action.…

Versions affectées

*-1.6.4

Correctif

1.6.5

Publication

10/07/2026

CVE-2024-6353 Élevée · 8,8
Wallet for WooCommerce

Wallet for WooCommerce <= 1.5.4 – Authenticated (Subscriber+) SQL Injection via 'search[value]'

The Wallet for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'search[value]' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

Versions affectées

*-1.5.4

Correctif

1.5.5

Publication

11/07/2024

CVE-2024-32584 Moyenne · 4,4
Wallet for WooCommerce

TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds <= 1.5.0 – Authenticated (Shop Manager+) Stored Cross-Site Scripting

The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.5.0 due to insufficient input sanitization…

Versions affectées

*-1.5.0

Correctif

1.5.1

Publication

24/04/2024

CVE-2024-1690 Moyenne · 4,3
Wallet for WooCommerce

TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds <= 1.4.10 – Missing Authorization to Authenticated (Subscriber+) User Email Export

The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the terawallet_export_user_search() function in all versions up…

Versions affectées

*-1.4.10

Correctif

1.4.11

Publication

07/03/2024

CVE-2022-36401 Élevée · 8,8
Wallet for WooCommerce

TeraWallet – For WooCommerce <= 1.3.24 – Cross-Site Request Forgery via lock_unlock_terawallet

The TeraWallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.24. This is due to missing nonce validation on the lock_unlock_terawallet function. This makes it possible for unauthenticated attackers to lock…

Versions affectées

*-1.3.24

Correctif

1.4.0

Publication

30/10/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités