Extension WordPress
Vulnérabilités WooCommerce, page 2
Cette page rassemble les failles publiées pour WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WooCommerce
44 fiches
WooCommerce < 5.5 – Authenticated Blind SQL Injection
Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 5.5. Malicious actors (already) having admin access, or API keys to the WooCommerce…
[*, 3.3), 3.3-3.3.5, 3.4-3.4.7, 3.5-3.5.8, 3.6-3.6.5, 3.7-3.7.1, 3.8-3.8.1, 3.9-3.9.3, 4.0-4.0.1, 4.1-4.1.1, 4.2-4.2.2, 4.3-4.3.3, 4.4-4.4.1, 4.5-4.5.2, 4.6-4.6.2, 4.7-4.7.1, 4.8, 4.9-4.9.2, 5.0, 5.1, 5.2-5.2.2, 5.3, 5.4-5.4.1, 5.5
3.3.6, 3.4.8, 3.5.9, 3.6.6, 3.7.2, 3.8.2, 3.9.4, 4.0.2, 4.1.2, 4.2.3, 4.3.4, 4.4.2, 4.5.3, 4.6.3, 4.7.2, 4.8.1, 4.9.3, 5.0.1, 5.1.1, 5.2.3, 5.3.1, 5.4.2, 5.5.1, 5.5.2
13/07/2021
WooCommerce <= 5.1.3 – Authenticated (Admin+) Stored Cross-Site Scripting
The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Additional tax classes' field when the tax functionality of WooCommerce is enabled in versions up to, and including, 5.1.3 due to insufficient input sanitization and…
[*, 5.2.0)
5.2.0
21/04/2021
WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 – Settings Bypass leading to Account Creation
The WooCommerce plugin for WordPress is vulnerable to unauthorized user account creation during checkout even when the “Allow customers to create an account during checkout” setting is disabled. was disabled due to missing authorization checks in versions up…
[*, 4.6.2)
4.6.2
05/11/2020
WooCommerce <= 4.2.0 – Reflected Cross-Site Scripting
The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing sanitization and escaping in SelectWoo, that makes it possible for attackers to inject arbitrary web scripts. This affects versions up to 4.2.1.
[*, 4.2.1)
4.2.1
22/06/2020
WooCommerce <= 4.0.4 – Unauthorized Post Meta Creation/Modification
The WooCommerce plugin for WordPress is vulnerable to arbitrary product meta data creation/overwriting due to a lack of escaping and validation on the post meta data being supplied during product duplication in versions up to, and including 4.0.4.…
[*, 4.1.0)
4.1.0
05/05/2020
WooCommerce < 4.7.0 – Insecure Direct Object Reference via order_id Parameter
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
[*, 4.7.0)
4.7.0
21/01/2020
WooCommerce <= 3.6.4 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 3.6.4, due to the CSV importer actions missing a nonce validation. This makes it possible for attackers with at least author…
[*, 3.6.5)
3.6.5
02/07/2019
WooCommerce <= 3.6.4 – Missing File Type Validation
The WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads via the tax rate importer due to missing file type validation that made it possible for high level authenticated attackers to upload malicious files in versions up…
*-3.6.4
3.6.5
02/07/2019
WooCommerce <= 3.5.4 – Stored Cross-Site Scripting
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
[*, 3.5.5)
3.5.5
20/02/2019
WooCommerce <= 3.5.1 – Authenticated Stored Cross-Site Scripting
The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting due to sanitization and escaping on an unspecific variable, that makes it possible for attackers to inject arbitrary web scripts into pages. This affects versions up to 3.5.0,…
*-3.5.1
3.5.2
29/11/2018
WooCommerce <= 3.4.5 – WooCommerce File Deletion
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop…
[*, 3.4.6)
3.4.6
06/11/2018
WooCommerce <= 3.4.4 – Authenticated PHP Object Injection
The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection by users with access to edit attributes in versions up to, and including 3.4.4.
[*, 3.4.5)
3.4.5
29/08/2018
WooCommerce <= 3.2.3 – Authenticated PHP Object Injection
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted…
[*, 3.2.4)
3.2.4
16/11/2017
WooCommerce <= 2.6.8 – Authenticated Stored Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.
[*, 2.6.9)
2.6.9
07/12/2016
WooCommerce <= 2.6.3 – Stored Cross-Site Scripting via REST-API
The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image uploader feature powered by the /wc-api/v3/products/categories/ REST-API in versions up to, and including, 2.6.3 due to insufficient filetype validation. This makes it possible for…
[*, 2.6.4)
2.6.4
26/07/2016
WooCommerce <= 2.6.2 – Stored Cross-Site Scripting
The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image EXIF metadata in versions up to, and including, 2.6.2 due to insufficient validation on image files EXIF content. This makes it possible for authenticated attackers…
[*, 2.6.3)
2.6.3
19/07/2016
WooCommerce < 2.4.9 – Cross-site Scripting
The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the pay_price() function, in versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator…
[*, 2.4.9)
2.4.9
17/11/2015
WooCommerce <= 2.3.10 – PHP Object Injection
The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.10 via deserialization of untrusted input from the $custom parameter. This allows authenticated attackers to inject a PHP Object. The additional…
*-2.3.10
2.3.11
10/06/2015
WooCommerce <= 2.3.5 – Stored Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.
[*, 2.3.6)
2.3.6
13/03/2015
WooCommerce <= 2.2.10 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php.
[*, 2.2.11)
2.2.11
29/01/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.