Extension WordPress
Vulnérabilités Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools, page 2
Cette page rassemble les failles publiées pour Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
38 fiches
Booster for WooCommerce <= 7.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-7.1.0
7.1.1
13/09/2023
Booster for WooCommerce 7.0.0 – Authenticated (Shop Manager+) Missing Authorization to Arbitrary Options Update
The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the 'manage_options' function in versions up to, and including, 7.0.0. This makes it possible for authenticated attackers…
7.0.0
7.1.0
01/08/2023
Booster (<= 6.0.0), Booster Plus (<= 6.0.0), and Booster Elite (<= 6.0.0) for WooCommerce – Cross-Site Request Forgery
The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.0 (Booster), 6.0.0 (Plus), and 6.0.0 (Elite). This is due to missing or incorrect nonce…
*-6.0.0
6.0.1
02/01/2023
Booster (<= 5.6.2), Booster Plus (< 6.0.0), and Booster Elite (< 6.0.0) for WooCommerce – Reflected Cross-Site Scripting
The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.2 (Booster), as well as versions below 6.0.0 (Plus and Elite). This is due to…
*-5.6.2
5.6.3
05/12/2022
Booster for WooCommerce <= 5.6.8 – Cross-Site Request Forgery
The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.8. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated…
*-5.6.8
6.0.0
30/11/2022
Booster (<= 5.6.6), Booster Plus (<= 5.6.5), and Booster Elite (<= 1.1.7) for WooCommerce – Cross-Site Request Forgery leading to Arbitrary Custom Role Creation/Deletion
The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Booster), 5.6.5 (Plus), and 1.1.7 (Elite). This is due to missing or incorrect nonce…
*-5.6.6
5.6.7
21/11/2022
Booster for WooCommerce (Free <= 5.6.6, Premium <= 5.6.4) – Cross-Site Request Forgery to File Deletion
The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Free) and 5.6.4 (Premium). This is due to missing or incorrect nonce validation when deleting files uploaded during…
*-5.6.6
5.6.7
31/10/2022
Booster (<= 5.6.6) and Booster Plus (<= 5.6.4) for WooCommerce – Authenticated (Shop Manager+) Information Exposure via Arbitrary File Download
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file downloads due to missing sanitization and filename validation of a user-supplied parameter in versions up to, and including, 5.6.6 (5.6.4 for Booster Plus). This makes it…
*-5.6.6
5.6.7
27/10/2022
Booster for WooCommerce <= 5.6.6 – Cross-Site Request Forgery
The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated…
*-5.6.6
5.6.7
27/10/2022
Booster for WooCommerce (Free <= 5.6.2 and Premium <= 5.6.0) – Authenticated (Subscriber+) Order Modification
The Booster for WooCommerce plugin for WordPress is vulnerable to order modification due to a missing capability/authorization check in versions up to, and including, 5.6.2 (free) or 5.6.0 (premium). This makes it possible for authenticated attackers, with subscriber-level…
*-5.6.2
5.6.3
19/09/2022
Booster for WooCommerce <= 5.6.1 – Cross-Site Request Forgery
The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.1. This is due to missing or incorrect nonce validation on several different functions. This makes it possible for…
*-5.6.1
5.6.2
27/07/2022
Booster for WooCommerce <= 5.5.9 – Reflected Cross-Site Scripting
The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web…
*-5.5.9
5.6.0
04/07/2022
Booster for WooCommerce <= 5.5.8 – Reflected Cross-Site Scripting
The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 5.5.8. This makes it possible for unauthenticated…
*-5.5.8
5.5.9
31/05/2022
Booster for WooCommerce <= 5.4.8 – Reflected Cross-Site Scripting in General Module
The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter before outputting back in the admin dashboard when the General module is enabled, leading to a Reflected Cross-Site Scripting issue
[*, 5.4.9)
5.4.9
01/12/2021
Booster for WooCommerce <= 5.4.8 – Reflected Cross-Site Scripting in PDF Invoicing Module
The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_notice parameter before outputting it back in the admin dashboard when the Pdf Invoicing module is enabled, leading to a Reflected Cross-Site Scripting
[*, 5.4.9)
5.4.9
01/12/2021
Booster for WooCommerce <= 5.4.8 – Reflected Cross-Site Scripting in Product XML Feeds Module
The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_create_products_xml_result parameter before outputting back in the admin dashboard when the Product XML Feeds module is enabled, leading to a Reflected Cross-Site Scripting issue
[*, 5.4.9)
5.4.9
01/12/2021
Booster for WooCommerce <= 5.4.3 – Authentication Bypass
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file.…
*-5.4.3
5.4.4
24/08/2021
Booster for WooCommerce <= 3.7.0 – Cross-Site Scripting
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
[*, 3.8.0)
3.8.0
28/07/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.