Extension WordPress
Vulnérabilités YITH WooCommerce Multi-step Checkout
Cette page rassemble les failles publiées pour YITH WooCommerce Multi-step Checkout, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de YITH WooCommerce Multi-step Checkout
3 fiches
YITH plugins by YITHEMES <= (Various Versions) – Cross-Site Request Forgery
Several YITHEMES plugins for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the create_log_file function. This makes it possible for unauthenticated attackers to create an error or debug log…
*-2.0.5
Non indiqué
11/11/2022
YITH plugins by YITHEMES <= (Various Versions) – Missing Authorization
Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the create_log_file function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the logs of the…
*-2.0.5
Non indiqué
11/11/2022
YIT Plugin Framework <= 3.3.8 – Authenticated Settings Change
Various versions of a various YITH WooCommerce plugins that use the YIT Plugin Framework through 3.3.8 are vulnerable to authorization bypass due to a missing capability check in the the 'save_toggle_element_options' function in .plugin-fw/lib/yit-plugin-panel-wc.php. This allows authenticated users…
*-1.7.4
1.7.5
31/10/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.