Extension WordPress
Vulnérabilités YITH Pre-Order for WooCommerce
Cette page rassemble les failles publiées pour YITH Pre-Order for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de YITH Pre-Order for WooCommerce
3 fiches
YITH plugins by YITHEMES <= (Various Versions) – Cross-Site Request Forgery
Several YITHEMES plugins for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the create_log_file function. This makes it possible for unauthenticated attackers to create an error or debug log…
*-2.5.0
2.6.0
11/11/2022
YITH plugins by YITHEMES <= (Various Versions) – Missing Authorization
Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the create_log_file function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the logs of the…
*-2.5.0
2.6.0
11/11/2022
YIT Plugin Framework <= 3.3.8 – Authenticated Settings Change
Various versions of a various YITH WooCommerce plugins that use the YIT Plugin Framework through 3.3.8 are vulnerable to authorization bypass due to a missing capability check in the the 'save_toggle_element_options' function in .plugin-fw/lib/yit-plugin-panel-wc.php. This allows authenticated users…
*-1.1.9
1.2.1
31/10/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.