Vulnerabilities
Vulnerable Software
Zixn:  Security Vulnerabilities
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the removeorder AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete Buy one click WooCommerce orders.
CVSS Score
4.3
EPSS Score
0.0
Published
2024-11-13
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import plugin settings.
CVSS Score
4.3
EPSS Score
0.0
Published
2024-11-13
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Djo VK Poster Group allows Reflected XSS.This issue affects VK Poster Group: from n/a through 2.0.3.
CVSS Score
7.1
EPSS Score
0.001
Published
2024-02-12
Cross-Site Request Forgery (CSRF) vulnerability in Djo Original texts Yandex WebMaster plugin <= 1.18 versions.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-11-06


Contact Us

Shodan ® - All rights reserved