Extension WordPress
Vulnérabilités Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools
Cette page rassemble les failles publiées pour Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools
5 fiches
WooCommerce Store Toolkit <= 2.4.3 – Unauthenticated Local File Inclusion
The WooCommerce Store Toolkit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.3. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…
*-2.4.3
2.4.4
15/07/2025
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.3.4)
2.3.4
04/03/2022
Store Toolkit for WooCommerce <= 2.3.1 – Reflected Cross-Site Scripting
The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting
[*, 2.3.2)
2.3.2
10/01/2022
Store Toolkit for WooCommerce <= 1.5.7 – Privilege Escalation
The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.7. This is due to improper privilege management. This makes it possible for authenticated attackers to bypass capability checks.
*-1.5.7
1.5.8
10/02/2016
Store Toolkit for WooCommerce <= 1.5.6 – Missing Authorization
The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to missing authorization checks on the woo_st_admin_init() function in versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to gain access to restricted administrative…
*-1.5.6
1.5.7
08/02/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.