Vulnerabilities
Vulnerable Software
Woocommerce:  >> Woocommerce  >> 1.1  Security Vulnerabilities
The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-10-15
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment
CVSS Score
4.3
EPSS Score
0.003
Published
2024-01-16
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-01-08
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin <= 1.3.25 versions.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-08-25
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
CVSS Score
4.8
EPSS Score
0.002
Published
2022-07-17
When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled
CVSS Score
4.8
EPSS Score
0.004
Published
2021-05-17
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
CVSS Score
5.3
EPSS Score
0.131
Published
2020-12-27
WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS) via includes/admin/importers/class-wc-product-csv-importer-controller.php.
CVSS Score
8.8
EPSS Score
0.001
Published
2020-06-19
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-02-26
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.
CVSS Score
8.8
EPSS Score
0.016
Published
2019-01-15


Contact Us

Shodan ® - All rights reserved