Extension WordPress

Vulnérabilités Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Cette page rassemble les failles publiées pour Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools, leurs plages de versions affectées et les correctifs signalés dans la base locale.

38Vulnérabilités
1Critiques
38Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

38 fiches

CVE-2026-56027 Élevée · 8,8
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools <= 8.0.1 – Authenticated (Customer+) Arbitrary File Upload

The Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 8.0.1. This…

Versions affectées

*-8.0.1

Correctif

8.0.2

Publication

23/06/2026

CVE-2026-32586 Moyenne · 5,3
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools < 7.11.3 – Missing Authorization

The Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 7.11.3 (exclusive).…

Versions affectées

[*, 7.11.3)

Correctif

7.11.3

Publication

17/03/2026

CVE-2025-64379 Moyenne · 4,3
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.4.0 – Missing Authorization

The Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-7.4.0

Correctif

7.5.0

Publication

30/10/2025

CVE-2025-64380 Moyenne · 6,4
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-7.3.2

Correctif

7.4.0

Publication

18/10/2025

CVE-2024-13342 Élevée · 8,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.2.4 – Unauthenticated Double Extension Arbitrary File Upload

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_order' function in all versions up to, and including, 7.2.4. This makes it possible for unauthenticated attackers…

Versions affectées

*-7.2.4

Correctif

7.2.5

Publication

28/08/2025

CVE-2025-64196 Moyenne · 6,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.2.5 – Reflected Cross-Site Scripting

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

Versions affectées

*-7.2.5

Correctif

7.2.6

Publication

22/04/2025

CVE-2024-13708 Élevée · 7,2
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce 4.0.1 – 7.2.4 – Unauthenticated Stored Cross-Site Scripting

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

4.0.1-7.2.4

Correctif

7.2.5

Publication

03/04/2025

CVE-2024-13744 Élevée · 8,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce 4.0.1 – 7.2.4 – Unauthenticated Arbitrary File Upload

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart function in versions 4.0.1 to 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary…

Versions affectées

4.0.1-7.2.4

Correctif

7.2.5

Publication

03/04/2025

CVE-2024-12278 Élevée · 7,2
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.2.4 – Unauthenticated Stored Cross-Site Scripting

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typically sanitizes data using wp_kses, like comments, in all versions up to, and including, 7.2.4 due to insufficient input sanitization and…

Versions affectées

*-7.2.4

Correctif

7.2.5

Publication

31/03/2025

CVE-2024-9170 Moyenne · 5,5
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.2.3 – Authenticated (ShopManager+) Stored Cross-Site Scripting via wcj_product_meta Shortcode

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, 7.2.3 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-7.2.3

Correctif

7.2.4

Publication

25/11/2024

CVE-2024-9239 Moyenne · 6,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.2.3 – Reflected Cross-Site Scripting

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.2.3. This makes it…

Versions affectées

*-7.2.3

Correctif

7.2.4

Publication

19/11/2024

CVE-2024-3957 Moyenne · 6,5
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.8 – Unauthenticated Arbitrary Shortcode Execution

The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installed…

Versions affectées

*-7.1.8

Correctif

7.1.9

Publication

01/05/2024

CVE-2024-29760 Moyenne · 6,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.7 – Reflected Cross-Site Scripting

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

Versions affectées

*-7.1.7

Correctif

7.1.8

Publication

25/03/2024

CVE-2024-1534 Moyenne · 6,4
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortocde

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This…

Versions affectées

*-7.1.7

Correctif

7.1.8

Publication

06/03/2024

CVE-2024-1054 Moyenne · 6,4
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wcj_product_barcode' shortcode in all versions up to, and including, 7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes…

Versions affectées

*-7.1.6

Correctif

7.1.7

Publication

12/02/2024

CVE-2023-48333 Moyenne · 4,3
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.1 – Missing Authorization to Authenticated (Subscriber+) Order Information Disclosure

The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_atts() function in all versions up to, and including, 7.1.1. This makes it possible for authenticated…

Versions affectées

*-7.1.1

Correctif

7.1.2

Publication

24/11/2023

CVE-2023-48747 Moyenne · 4,3
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.2 – Missing Authorization to Product Creation/Modification

The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcj_product_add_new() function in all versions up to, and including, 7.1.2. This makes it possible for authenticated…

Versions affectées

*-7.1.2

Correctif

7.1.3

Publication

24/11/2023

CVE-2023-5638 Moyenne · 6,4
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode in versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

Versions affectées

*-7.1.2

Correctif

7.1.3

Publication

18/10/2023

CVE-2023-40002 Moyenne · 4,3
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.1 – Authenticated (Subscriber+) Information Disclosure via Shortcode

The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_get_option' shortcode in versions up to, and including, 7.1.1 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for…

Versions affectées

*-7.1.1

Correctif

7.1.2

Publication

04/10/2023

CVE-2023-4796 Moyenne · 4,3
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.0 – Authenticated (Subscriber+) Information Disclosure via Shortcode

The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in versions up to, and including, 7.1.0 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for…

Versions affectées

*-7.1.0

Correctif

7.1.1

Publication

13/09/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités