Extension WordPress

Vulnérabilités Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools, page 2

Cette page rassemble les failles publiées pour Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools, leurs plages de versions affectées et les correctifs signalés dans la base locale.

38Vulnérabilités
1Critiques
38Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

38 fiches

CVE-2023-4945 Moyenne · 6,4
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 7.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

Versions affectées

*-7.1.0

Correctif

7.1.1

Publication

13/09/2023

Vulnérabilité Élevée · 7,2
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce 7.0.0 – Authenticated (Shop Manager+) Missing Authorization to Arbitrary Options Update

The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the 'manage_options' function in versions up to, and including, 7.0.0. This makes it possible for authenticated attackers…

Versions affectées

7.0.0

Correctif

7.1.0

Publication

01/08/2023

CVE-2022-4017 Moyenne · 5,4
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster (<= 6.0.0), Booster Plus (<= 6.0.0), and Booster Elite (<= 6.0.0) for WooCommerce – Cross-Site Request Forgery

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.0 (Booster), 6.0.0 (Plus), and 6.0.0 (Elite). This is due to missing or incorrect nonce…

Versions affectées

*-6.0.0

Correctif

6.0.1

Publication

02/01/2023

CVE-2022-4227 Moyenne · 6,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster (<= 5.6.2), Booster Plus (< 6.0.0), and Booster Elite (< 6.0.0) for WooCommerce – Reflected Cross-Site Scripting

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.2 (Booster), as well as versions below 6.0.0 (Plus and Elite). This is due to…

Versions affectées

*-5.6.2

Correctif

5.6.3

Publication

05/12/2022

Vulnérabilité Élevée · 8,8
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 5.6.8 – Cross-Site Request Forgery

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.8. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated…

Versions affectées

*-5.6.8

Correctif

6.0.0

Publication

30/11/2022

CVE-2022-4016 Moyenne · 5,4
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster (<= 5.6.6), Booster Plus (<= 5.6.5), and Booster Elite (<= 1.1.7) for WooCommerce – Cross-Site Request Forgery leading to Arbitrary Custom Role Creation/Deletion

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Booster), 5.6.5 (Plus), and 1.1.7 (Elite). This is due to missing or incorrect nonce…

Versions affectées

*-5.6.6

Correctif

5.6.7

Publication

21/11/2022

CVE-2022-3763 Élevée · 8,8
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce (Free <= 5.6.6, Premium <= 5.6.4) – Cross-Site Request Forgery to File Deletion

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Free) and 5.6.4 (Premium). This is due to missing or incorrect nonce validation when deleting files uploaded during…

Versions affectées

*-5.6.6

Correctif

5.6.7

Publication

31/10/2022

CVE-2022-3762 Moyenne · 6,5
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster (<= 5.6.6) and Booster Plus (<= 5.6.4) for WooCommerce – Authenticated (Shop Manager+) Information Exposure via Arbitrary File Download

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file downloads due to missing sanitization and filename validation of a user-supplied parameter in versions up to, and including, 5.6.6 (5.6.4 for Booster Plus). This makes it…

Versions affectées

*-5.6.6

Correctif

5.6.7

Publication

27/10/2022

CVE-2022-41805 Élevée · 8,8
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 5.6.6 – Cross-Site Request Forgery

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated…

Versions affectées

*-5.6.6

Correctif

5.6.7

Publication

27/10/2022

Vulnérabilité Moyenne · 6,5
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce (Free <= 5.6.2 and Premium <= 5.6.0) – Authenticated (Subscriber+) Order Modification

The Booster for WooCommerce plugin for WordPress is vulnerable to order modification due to a missing capability/authorization check in versions up to, and including, 5.6.2 (free) or 5.6.0 (premium). This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-5.6.2

Correctif

5.6.3

Publication

19/09/2022

Vulnérabilité Élevée · 8,8
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 5.6.1 – Cross-Site Request Forgery

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.1. This is due to missing or incorrect nonce validation on several different functions. This makes it possible for…

Versions affectées

*-5.6.1

Correctif

5.6.2

Publication

27/07/2022

Vulnérabilité Moyenne · 6,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 5.5.9 – Reflected Cross-Site Scripting

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web…

Versions affectées

*-5.5.9

Correctif

5.6.0

Publication

04/07/2022

Vulnérabilité Moyenne · 6,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 5.5.8 – Reflected Cross-Site Scripting

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 5.5.8. This makes it possible for unauthenticated…

Versions affectées

*-5.5.8

Correctif

5.5.9

Publication

31/05/2022

CVE-2021-25000 Moyenne · 6,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 5.4.8 – Reflected Cross-Site Scripting in General Module

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter before outputting back in the admin dashboard when the General module is enabled, leading to a Reflected Cross-Site Scripting issue

Versions affectées

[*, 5.4.9)

Correctif

5.4.9

Publication

01/12/2021

CVE-2021-24999 Moyenne · 6,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 5.4.8 – Reflected Cross-Site Scripting in PDF Invoicing Module

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_notice parameter before outputting it back in the admin dashboard when the Pdf Invoicing module is enabled, leading to a Reflected Cross-Site Scripting

Versions affectées

[*, 5.4.9)

Correctif

5.4.9

Publication

01/12/2021

CVE-2021-25001 Moyenne · 6,1
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 5.4.8 – Reflected Cross-Site Scripting in Product XML Feeds Module

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_create_products_xml_result parameter before outputting back in the admin dashboard when the Product XML Feeds module is enabled, leading to a Reflected Cross-Site Scripting issue

Versions affectées

[*, 5.4.9)

Correctif

5.4.9

Publication

01/12/2021

CVE-2021-34646 Critique · 9,8
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Booster for WooCommerce <= 5.4.3 – Authentication Bypass

Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file.…

Versions affectées

*-5.4.3

Correctif

5.4.4

Publication

24/08/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités