Extension WordPress
Vulnérabilités Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices
Cette page rassemble les failles publiées pour Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices
6 fiches
Wholesale Suite <= 2.2.6 – Authenticated (Shop Manager) Privilege Escalation
The Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.6.This makes it possible for authenticated attackers, with Shop Manager-level access and…
*-2.2.6
2.2.7
20/02/2026
Wholesale Suite <= 2.2.4.2 – Authenticated (Shop Manager+) Privilege Escalation
The Wholesale Suite – B2B, Dynamic Pricing & Wholesale Prices for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.4.2. This makes it possible for authenticated attackers, with Shop Manager-level…
*-2.2.4.2
2.2.5
23/07/2025
Wholesale Suite <= 2.1.12 – Missing Authorization
The Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all…
*-2.1.12
2.2.0
11/07/2024
Wholesale Suite <= 2.1.5 – Missing Authorization to Plugin Settings Change
The Wholesale Suite plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the edit_wholesale_role function in versions up to, and including, 2.1.5. This makes it possible for authenticated attackers with subscriber-level…
*-2.1.5
2.1.6
27/02/2023
Wholesale Suite <= 2.1.5 – Authenticated (Subscriber+) Cross-Site Scripting
The Wholesale Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'role' parameters in versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level, and…
*-2.1.5
2.1.5.1
28/11/2022
Wholesale Suite <= 2.1.5 – Cross-Site Request Forgery
The Wholesale Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.5. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers…
*-2.1.5
2.1.5.1
19/10/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.