Extension WordPress

Vulnérabilités WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce

Cette page rassemble les failles publiées pour WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
0Critiques
4Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce

4 fiches

CVE-2026-42748 Élevée · 8,8
WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce

WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce <= 5.4.1 – Authenticated (Contributor+) Arbitrary File Upload

The WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 5.4.1. This makes…

Versions affectées

*-5.4.1

Correctif

5.4.2

Publication

29/05/2026

CVE-2024-33946 Moyenne · 6,1
WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce

WPify Woo Czech <= 4.0.10 – Reflected Cross-Site Scripting

The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-4.0.10

Correctif

4.0.11

Publication

30/04/2024

CVE-2024-1492 Moyenne · 5,3
WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce

WPify Woo Czech <= 4.0.8 – Missing Authorization

The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta function in all versions up to, and including, 4.0.8. This makes it possible for unauthenticated…

Versions affectées

*-4.0.8

Correctif

4.0.9

Publication

19/02/2024

Vulnérabilité Moyenne · 6,1
WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce

WPify Woo Czech <= 3.5.6 – Reflected Cross-Site Scripting

The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of '$_SERVER['PHP_SELF']' with insufficient input sanitization and output escaping in versions up to, and including, 3.5.6. This makes it possible for…

Versions affectées

*-3.5.6

Correctif

3.5.7

Publication

16/05/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités