Extension WordPress
Vulnérabilités WooCommerce – PDF Vouchers
Cette page rassemble les failles publiées pour WooCommerce – PDF Vouchers, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WooCommerce – PDF Vouchers
6 fiches
WooCommerce PDF Vouchers < 4.9.9 – Reflected Cross-Site Scripting
The WooCommerce – PDF Vouchers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 4.9.9 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 4.9.9)
4.9.9
19/12/2024
WooCommerce PDF Vouchers < 4.9.9 – Authentication Bypass
The WooCommerce – PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in all versions up to 4.9.9 (exclusive). This makes it possible for unauthenticated attackers to log in as other users.
[*, 4.9.9)
4.9.9
11/12/2024
WooCommerce PDF Vouchers <= 4.9.4 – Missing Authorization
The WooCommerce – PDF Vouchers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like 'woo_vou_trigger_upgrades', 'woo_vou_admin_run_v430_udater_script', 'woo_vou_activate_license', 'woo_vou_generate_system_log' and many more in all versions up to, and including 4.9.4.…
*-4.9.4
4.9.5
01/08/2024
WooCommerce PDF Vouchers <= 4.9.4 – Reflected Cross-Site Scripting
The WooCommerce – PDF Vouchers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-4.9.4
4.9.5
01/08/2024
WooCommerce PDF Vouchers <= 4.9.4 – Unauthenticated Arbitrary File Deletion
The WooCommerce – PDF Vouchers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 4.9.4. This makes it possible for unauthenticated attackers…
*-4.9.4
4.9.5
01/08/2024
WooCommerce – PDF Vouchers <= 4.9.3 – Authentication Bypass to Voucher Vendor
The WooCommerce – PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient verification on the user being supplied during a QR code login through the…
*-4.9.3
4.9.4
23/07/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.