Extension WordPress
Vulnérabilités YITH Request a Quote for WooCommerce
Cette page rassemble les failles publiées pour YITH Request a Quote for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de YITH Request a Quote for WooCommerce
5 fiches
YITH WooCommerce Request A Quote <= 2.46.0 – Missing Authorization
The YITH Request a Quote for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.46.0. This makes it possible for unauthenticated…
*-2.46.0
2.46.1
09/01/2026
YITH plugins by YITHEMES <= (Various Versions) – Cross-Site Request Forgery
Several YITHEMES plugins for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the create_log_file function. This makes it possible for unauthenticated attackers to create an error or debug log…
*-2.15.0
2.15.1
11/11/2022
YITH plugins by YITHEMES <= (Various Versions) – Missing Authorization
Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the create_log_file function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the logs of the…
*-2.15.0
2.15.1
11/11/2022
YITH Request a Quote for WooCommerce <= 1.6.3 – Cross-Site Request Forgery
The YITH Request a Quote for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.3. This is due to missing or incorrect nonce validation on the several functions. This makes…
*-1.6.3
1.6.4
30/06/2021
YIT Plugin Framework <= 3.3.8 – Authenticated Settings Change
Various versions of a various YITH WooCommerce plugins that use the YIT Plugin Framework through 3.3.8 are vulnerable to authorization bypass due to a missing capability check in the the 'save_toggle_element_options' function in .plugin-fw/lib/yit-plugin-panel-wc.php. This allows authenticated users…
*-1.4.7
1.4.9
31/10/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.