Vulnerability Details CVE-2021-25018
The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored XSS issues
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.8%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2021-25018
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:1.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:1.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:10.10
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:10.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:10.7
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:10.8
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:10.9
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.7
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.8
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:11.9
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.7
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.8
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:12.9
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:13.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:13.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:13.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:13.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:13.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:13.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:13.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:13.7
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:14.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:14.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:14.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:14.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:15.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:15.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:15.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:15.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:15.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:15.4.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:15.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.7
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.8
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:16.9
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:17.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:17.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:17.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:17.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:17.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:17.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.7
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.8
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:18.9
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:19.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.7
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.8
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:2.9
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:20.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:20.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:20.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:20.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:20.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:20.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:21.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:21.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:21.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:22.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:22.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:22.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:22.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:22.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:22.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:22.7
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:22.8
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.7
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.8
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:23.9
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:3.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:3.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:3.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:3.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:3.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:3.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:3.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:4.0
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:4.1
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:4.2
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:4.3
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:4.4
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:4.5
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:4.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:5.6
-
cpe:2.3:a:najeebmedia:ppom_for_woocommerce:8.3