Extension WordPress
Vulnérabilités CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce
Cette page rassemble les failles publiées pour CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce
5 fiches
Product Catalog Enquiry for WooCommerce by MultiVendorX <= 5.0.5 – Cross-Site Request Forgery via REST API
The Product Catalog Enquiry for WooCommerce by MultiVendorX plugin for WordPress is vulnerable to cross-site request forgery due to an improper capability check on the 'catalog_permission' function in versions up to, and including, 5.0.5. While the REST endpoints…
*-5.0.5
5.0.6
20/02/2024
Product Catalog Mode For WooCommerce <= 5.0.2 – Unauthenticated Stored Cross-Site Scripting
The Product Catalog Mode For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_hover_background_color' parameter in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it…
*-5.0.2
5.0.3
21/11/2023
Product Catalog Mode For Woocommerce <= 5.0.2 – Missing Authorization
The Product Catalog Mode For Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the dismiss_mvx_catalog_servive_notice function in all versions up to 5.0.3 (exclusive). This makes it possible for…
[*, 5.0.3)
5.0.3
03/11/2023
Product Catalog Enquiry <= 5.0.2 – Missing Authorization
The Product Catalog Mode For Woocommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to an improper capability check on the catalog_rest_routes_react_module REST endpoints in all versions up to 5.0.3 (exclusive). This makes…
[*, 5.0.3)
5.0.3
03/11/2023
WC Catalog Enquiry <= 3.0.5 – Arbitrary File Upload
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
*-3.0.5
3.1.0
20/04/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.