Extension WordPress

Vulnérabilités Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools

Cette page rassemble les failles publiées pour Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools

5 fiches

CVE-2025-60204 Élevée · 8,1
Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools

WooCommerce Store Toolkit <= 2.4.3 – Unauthenticated Local File Inclusion

The WooCommerce Store Toolkit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.3. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…

Versions affectées

*-2.4.3

Correctif

2.4.4

Publication

15/07/2025

CVE-2022-4974 Moyenne · 6,3
Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 2.3.4)

Correctif

2.3.4

Publication

04/03/2022

CVE-2016-10923 Élevée · 8,8
Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools

Store Toolkit for WooCommerce <= 1.5.7 – Privilege Escalation

The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.7. This is due to improper privilege management. This makes it possible for authenticated attackers to bypass capability checks.

Versions affectées

*-1.5.7

Correctif

1.5.8

Publication

10/02/2016

CVE-2016-10922 Élevée · 8,8
Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools

Store Toolkit for WooCommerce <= 1.5.6 – Missing Authorization

The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to missing authorization checks on the woo_st_admin_init() function in versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to gain access to restricted administrative…

Versions affectées

*-1.5.6

Correctif

1.5.7

Publication

08/02/2016

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités