https://www.wpvulnerability.net/plugin/woocommerce/

{“error”:0,”message”:null,”data”:{“name”:”WooCommerce”,”plugin”:”woocommerce”,”link”:”https:\/\/wordpress.org\/plugins\/woocommerce\/”,”latest”:”1761317940″,”closed”:0,”vulnerability”:[{“uuid”:”c29a671a61f6f52d9ecf456a4c5ab51d538b20a83a54dde00040dd6326e65173″,”name”:”WooCommerce [woocommerce] < 6.6.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-32790","name":"CVE-2021-32790","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-32790","description":"[en] Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `\/wp-json\/wc\/v3\/webhooks`, `\/wp-json\/wc\/v2\/webhooks` and other webhook listing API. Read-only SQL queries can be executed using this exploit, while data will not be returned, by carefully crafting `search` parameter information can be disclosed using timing and related attacks. Version 3.3.6 is the earliest version of Woocommerce with a patch for this vulnerability. There are no known workarounds other than upgrading.","date":"2021-07-26"},{"id":"07dd9b41c96166bb6fd47fd1071ad107aa166842","name":"WooCommerce < 5.5 - Authenticated Blind SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-55-authenticated-blind-sql-injection","description":"Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 5.5. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `\/wp-json\/wc\/v3\/webhooks`, `\/wp-json\/wc\/v2\/webhooks` and other webhook listing API. Read-only SQL queries can be executed using this exploit, while data will not be returned, by carefully crafting `search` parameter information can be disclosed using timing and related attacks. Version 3.3.6 is the earliest version of Woocommerce with a patch for this vulnerability. There are no known workarounds other than upgrading.","date":"2021-07-13"},{"id":"1212fec8-1fde-41e5-af70-abdd7ffe5379","name":"Woocommerce 3.3 to 5.5 - Authenticated Blind SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/1212fec8-1fde-41e5-af70-abdd7ffe5379","description":"The plugin was reported to be affected by a critical Authenticated Blind SQL Injection vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"58a723f73406666b656a45f73eb2bfec08bcfb20358e4451cd3d2e3d41136947","name":"WooCommerce [woocommerce] < 5.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24323","name":"CVE-2021-24323","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24323","description":"[en] When taxes are enabled, the \"Additional tax classes\" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled","date":"2021-05-17"},{"id":"dbdb4f00ac6ac3abaed2a44f570eb67aa75d9a42","name":"WooCommerce <= 5.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-513-authenticated-admin-stored-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Additional tax classes' field when the tax functionality of WooCommerce is enabled in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2021-04-21"},{"id":"6d262555-7ae4-4e36-add6-4baa34dc3010","name":"Woocommerce < 5.2.0 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/6d262555-7ae4-4e36-add6-4baa34dc3010","description":"When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"4b363f520e576867082deb70c1cab2927b5b2e275c0a04b2161f62feec18e90c","name":"WooCommerce [woocommerce] < 4.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-29156","name":"CVE-2020-29156","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-29156","description":"[en] The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.","date":"2020-12-27"},{"id":"d084a12df6882bf16f632f53da60725739dca603","name":"WordPress WooCommerce plugin <= 4.6.2 - Sensitive Information Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-4-6-2-sensitive-information-disclosure-vulnerability","description":"Sensitive Information Disclosure vulnerability found in WordPress WooCommerce plugin (versions <= 4.6.2).","date":"2020-11-10"},{"id":"808be6dca292804e1f46cc08648cb25d345b55d5","name":"WooCommerce < 4.7.0 - Insecure Direct Object Reference via order_id Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-470-insecure-direct-object-reference-via-order-id-parameter","description":"The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.","date":"2020-01-21"},{"id":"c420f079-5803-47ec-9844-28b0785c35f0","name":"WooCommerce < 4.7.0 - Arbitrary Order Status Disclosure via IDOR","link":"https:\/\/wpscan.com\/vulnerability\/c420f079-5803-47ec-9844-28b0785c35f0","description":""The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action."","date":null}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}]}},{"uuid":"7b255fd9cf4f483267b9ae87884c3ad72172942a26a8587bce4e5492a8a91b1d","name":"WooCommerce [woocommerce] < 3.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-18356","name":"CVE-2017-18356","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-18356","description":"[en] In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes\/shortcodes\/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.","date":"2019-01-15"},{"id":"488e8c1e599cf72a6c1afcd12e1d26fd51118b2a","name":"WooCommerce <= 3.2.3 - Authenticated PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-323-authenticated-php-object-injection","description":"In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes\/shortcodes\/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.","date":"2017-11-16"},{"id":"1d0470df-4671-47ac-8d87-a165e8f7d502","name":"WooCommerce <= 3.2.3 - Authenticated PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/1d0470df-4671-47ac-8d87-a165e8f7d502","description":"Versions 3.2.3 and earlier are affected by an issue where cached queries within shortcodes could lead to object injection. This is related to the recent WordPress 4.8.3 security release.\r\n\r\nThis issue can only be exploited by users who can edit content and add shortcodes, but we still recommend all users running WooCommerce 3.x upgrade to 3.2 to mitigate this issue.","date":null}],"impact":{"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}]}},{"uuid":"1f6fe0660fcd9281bd4a393f08182ff896eb555c74cbbb3642a209460bcf4c33","name":"WooCommerce [woocommerce] < 3.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-20714","name":"CVE-2018-20714","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-20714","description":"[en] The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.","date":"2019-01-15"},{"id":"2cff67bd149d844bf4c454e43630840eabca92a2","name":"WooCommerce <= 3.4.5 - WooCommerce File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-345-woocommerce-file-deletion","description":"The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.","date":"2018-11-06"},{"id":"ad7f42a7-1ffb-4613-864a-6ae3249d8e10","name":"WooCommerce <= 3.4.5 - Authenticated File Deletion to Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/ad7f42a7-1ffb-4613-864a-6ae3249d8e10","description":"Attackers in control of a user with the shop manager role can delete certain files on the server and then take over any victim account.","date":null}],"impact":{"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"599e47aac8e385d43185ad9e2bfc0d19e1d83e92f609cead29cc15cc2623429b","name":"WooCommerce [woocommerce] >= 2.3 – <= 2.3.5","description":null,"operator":{"min_version":"2.3","min_operator":"ge","max_version":"2.3.5","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-2329","name":"CVE-2015-2329","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-2329","description":"[en] Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.","date":"2018-02-08"},{"id":"37646a8217c0acfd61b0625fc26226a796fa0640","name":"WooCommerce <= 2.3.5 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-235-stored-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.","date":"2015-03-13"},{"id":"7f1ab25f-4171-48a6-a67c-fa6020c7a0d6","name":"WooCommerce 2.3 - 2.3.5 - SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/7f1ab25f-4171-48a6-a67c-fa6020c7a0d6","description":"The WooCommerce WordPress plugin was affected by a 2.3.5 - SQL Injection security vulnerability.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"5afc4e3236976c9dd4887164d299b2d8af9926ff84caacef128c12e07e471d71","name":"WooCommerce [woocommerce] < 4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-17058","name":"CVE-2017-17058","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-17058","description":"[en] The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a \/wp-content\/plugins\/woocommerce\/templates\/emails\/plain\/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traversal is not possible because all of the template files have \"if (!defined('ABSPATH')) {exit;}\" code","date":"2017-11-29"}],"impact":{"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"ed64b0ab32a90743c8dfb4d83d1d906188abd1333c2d77a6bea59dcbcc872a94","name":"WooCommerce [woocommerce] < 2.6.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-10112","name":"CVE-2016-10112","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-10112","description":"[en] Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.","date":"2017-01-04"},{"id":"316f4d42371987f699adf0e13c7fcb466465a330","name":"WordPress WooCommerce Plugin <= 2.6.8 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-6-8-cross-site-scripting","description":"This plugin is prone to a cross site scripting vulnerability. It allows remote authenticated administrators to inject arbitrary code by manipulating tax-rate table values in CSV format.\nUpdate the plugin.","date":"2017-01-03"},{"id":"7a08ad8d2f1541b83d1205aa6921e0f297867fe9","name":"WooCommerce <= 2.6.8 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-268-authenticated-stored-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.","date":"2016-12-07"},{"id":"037bf4b0-889e-4af3-8ede-efbd5f71f3e3","name":"WooCommerce <= 2.6.8 - Authenticated Tax-Rate CSV XSS","link":"https:\/\/wpscan.com\/vulnerability\/037bf4b0-889e-4af3-8ede-efbd5f71f3e3","description":"The WooCommerce WordPress plugin was affected by an Authenticated Tax-Rate CSV XSS security vulnerability.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f56e89fa9510cca25e09314b28aefbad4be140de02b00c21fd0b061fbaaa1b55","name":"WooCommerce [woocommerce] < 2.2.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-2069","name":"CVE-2015-2069","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-2069","description":"[en] Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin\/admin.php.","date":"2015-02-24"},{"id":"5f940a53f25672dae0891f7abd261f639f913630","name":"WordPress WooCommerce Plugin <= 2.2.10 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-2-10-xss","description":"Because of this vulnerability, an attacker can inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin\/admin.php.\nUpdate to version 2.2.11.","date":"2015-02-24"},{"id":"aa717cb15c222b9adda093abd56444b859cbebf4","name":"WooCommerce <= 2.2.10 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-2210-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin\/admin.php.","date":"2015-01-29"},{"id":"301c83b2-a326-42f5-ad27-92845716dcd3","name":"WooCommerce <= 2.2.10 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/301c83b2-a326-42f5-ad27-92845716dcd3","description":"The WooCommerce WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d118b0d522e50c991f7d8ed749de47f7d0401771bb7eccbb9c54bc68bf550b89","name":"WooCommerce [woocommerce] < 2.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-6313","name":"CVE-2014-6313","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-6313","description":"[en] Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin\/admin.php.","date":"2014-10-14"},{"id":"45f25f88f013731b457084f589cd445fe676bc0e","name":"WordPress WooCommerce plugin <= 2.2.2 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-2-2-xss","description":"Cross-Site Scripting (XSS) vulnerability discovered by Tom Adams in WordPress WooCommerce plugin (versions <= 2.2.2).\nUpdate the WordPress WooCommerce plugin to the latest available version (at least 2.2.3).","date":"2014-09-11"},{"id":"e63fbb7ae11b5d34bea10aa12182312561664ebb","name":"WooCommerce <= 2.2.2 - Cross-Site Scripting via range Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-222-cross-site-scripting-via-range-parameter","description":"Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin\/admin.php.","date":"2014-09-15"},{"id":"1c0eced1-f1ff-475b-ba41-2d821bec5094","name":"WooCommerce <= 2.2.2 - Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/1c0eced1-f1ff-475b-ba41-2d821bec5094","description":"The WooCommerce WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"07ccc3b2848a2a405965a58204b7254440d2e3ac3615619def3f9279374574f7","name":"WooCommerce [woocommerce] < 6.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"695aa44ecdb912129467df2e622b85992bf865c1","name":"WordPress WooCommerce plugin <= 6.3.0 - Orders Status Change (via PayPal Standard Gateway) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-6-3-0-orders-status-change-via-paypal-standard-gateway-vulnerability","description":"Orders Status Change (via PayPal Standard Gateway) vulnerability discovered in WordPress WooCommerce plugin (versions <= 6.3.0).","date":"2022-03-10"}],"impact":[]},{"uuid":"0159e64c88233db83a11b961ab3a16e84761e0939f0791e1cdb2baffc91ecc6d","name":"WooCommerce [woocommerce] < 6.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7a219320d6ead92e02fde1f9b7c4a51feec217cc","name":"WordPress WooCommerce plugin <= 6.2.0 - Path Traversal via Importers vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-6-2-0-path-traversal-via-importers-vulnerability","description":"Path Traversal via Importers vulnerability discovered in WordPress WooCommerce plugin (versions <= 6.2.0).","date":"2022-02-23"}],"impact":[]},{"uuid":"b00d0b4a6105f2be1f29664e6eefc826be30677ec79ee91baec35dd9e6607ca9","name":"WooCommerce [woocommerce] < 6.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7ff0b9435a94549e23225d1163a9592fdfb8e1b9","name":"WordPress WooCommerce plugin <= 6.2.0 - Arbitrary Comment Deletion vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-6-2-0-arbitrary-comment-deletion-vulnerability","description":"Arbitrary Comment Deletion vulnerability discovered in WordPress WooCommerce plugin (versions <= 6.2.0).","date":"2022-02-23"}],"impact":[]},{"uuid":"2d0c2ee5a99c15b9a2009aeccc50278b1aa1eef0647ea21b5d814e790d0813f9","name":"WooCommerce [woocommerce] < 5.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3d8ef05141df6232add605c1a5ee1ec2390d6a7d","name":"WordPress WooCommerce plugin <= 5.6.0 - Analytics Report Leaks vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-5-6-0-analytics-report-leaks-vulnerability","description":"Analytics Report Leaks vulnerability discovered in the WordPress WooCommerce plugin (versions <= 5.6.0).","date":"2021-09-22"}],"impact":[]},{"uuid":"92bb33ae30647f901d75d0287e1d7bb76706578049577f7c79f9ff18b0fdfbce","name":"WooCommerce [woocommerce] < 5.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"66aea82791db33970a12e7f7d7e8125ef6ee9d30","name":"WordPress WooCommerce plugin <= 5.5.0 - Unauthenticated SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-5-5-0-sql-injection-sqli-vulnerability","description":"Unauthenticated SQL Injection (SQLi) vulnerability discovered in WordPress WooCommerce plugin (versions <= 5.5.0).","date":"2021-07-15"}],"impact":[]},{"uuid":"72dac1cfa68db0a8869af4b2dd440295d85d4464d1f08f46be4c32704475c4ad","name":"WooCommerce [woocommerce] < 5.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ab4a39c1f4c6f48c4dd41a7c121d574503bc9707","name":"WordPress WooCommerce plugin <= 5.1.0 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-5-1-0-authenticated-persistent-cross-site-scripting-xss-vulnerability","description":"Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress WooCommerce plugin (versions <= 5.1.0).","date":"2021-04-29"}],"impact":[]},{"uuid":"2f6dda7b6eb2be9e4295c24ef46d24fa7d84b7f887088c42b6442313cd0412ff","name":"WooCommerce [woocommerce] < 4.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6ab7d4fa44f0eff509b12cc4ae5ae9923df385b4","name":"WordPress WooCommerce plugin <= 4.6.1 - Guest Account Creation vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-4-6-1-guest-account-creation-vulnerability","description":"Guest Account Creation vulnerability found in WordPress WooCommerce plugin (versions <= 4.6.1).","date":"2020-11-06"}],"impact":[]},{"uuid":"fc722ffc6366c3fa123848e574bb04a38f59601c5e048668a1158e687e696b03","name":"WooCommerce [woocommerce] < 3.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5649347acd519397ed92ba6eb281e90adb3d0c9a","name":"WordPress WooCommerce plugin <= 3.6.4 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-3-6-4-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WooCommerce plugin (versions <= 3.6.4).","date":"2019-07-07"}],"impact":[]},{"uuid":"62bc5a74eaa29d30f977664c1ca005b8e259d580067aa76553775d6360fff5d6","name":"WooCommerce [woocommerce] < 3.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-9168","name":"CVE-2019-9168","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-9168","description":"[en] WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.","date":"2019-02-26"},{"id":"121d37ec30498106c1d2cd05440a9590f08da4f1","name":"WordPress WooCommerce plugin <= 3.5.4 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-3-5-4-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability found by Fortinet's FortiGuard Labs (Zhouyuan Yang) in WordPress WooCommerce plugin (versions <= 3.5.4).","date":"2019-02-26"},{"id":"b2bc7913a956fdf21671fe0f684304fd4f65bf0e","name":"WooCommerce <= 3.5.4 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-354-stored-cross-site-scripting","description":"WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.","date":"2019-02-20"},{"id":"661a5cd0-f152-4a33-8de8-55fa9f73c8d4","name":"WooCommerce <= 3.5.4 - Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/661a5cd0-f152-4a33-8de8-55fa9f73c8d4","description":"* Security - Improved escaping for Photoswipe captions.\r\n* Security - Improved escaping for JSON attributes and structured data.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"585ce4dd1d48d39225cb55ab7e927f1cee03a88d9080adab4a88a8acf91d3ad1","name":"WooCommerce [woocommerce] < 3.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7c1c4809008b686d1aa8e43a301747a5c1f09590","name":"WordPress WooCommerce plugin <= 3.5.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-3-5-0-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Ripstech in WordPress WooCommerce plugin (versions <= 3.5.0).","date":"2019-01-07"}],"impact":[]},{"uuid":"1c55075efed976177bca04d09559750bce5792df66011b02feb91d425d4c33e6","name":"WooCommerce [woocommerce] < 3.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5e222706e0976f2c77ee775b6e408fb92415f933","name":"WordPress WooCommerce plugin <= 3.4.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-3-4-5-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability found in WordPress WooCommerce plugin (versions <= 3.4.5).","date":"2018-12-11"}],"impact":[]},{"uuid":"1e428416175dd93b361a2221ef6d148364dcc535f0a0cda8bfe2b75fca105e60","name":"WooCommerce [woocommerce] < 3.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2881ce043809d154cf85a5ac2008f864e22266e6","name":"WordPress WooCommerce plugin <= 3.4.5 - Authenticated File Deletion to Privilege Escalation vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-3-4-5-authenticated-file-deletion-to-privilege-escalation-vulnerability","description":"Authenticated File Deletion to Privilege Escalation vulnerability found in WordPress WooCommerce plugin (versions <= 3.4.5).","date":"2018-11-07"}],"impact":[]},{"uuid":"86f439a16ac74aa69ccbfd3de462e8371eed6b4651e96589574038da55b4e14c","name":"WooCommerce [woocommerce] < 3.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7f16eef33696b69f02c41228a121f5ccc186784d","name":"WordPress WooCommerce plugin <= 3.4.5 - Authenticated Object Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-3-4-5-authenticated-object-injection-vulnerability","description":"Authenticated Object Injection vulnerability found by Slavco in WordPress WooCommerce plugin (versions <= 3.4.5).","date":"2018-10-29"}],"impact":[]},{"uuid":"0341df8ecd693ab9fedb9bf8e71b2589ef5cc2530c8df060f74c1dc7d62a6e7f","name":"WooCommerce [woocommerce] < 3.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3112a20e2a44be5d3b691aa2a82da1db9de1e571","name":"WordPress WooCommerce plugin <= 3.4.4 - Potential Object Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-3-4-4-potential-object-injection-vulnerability","description":"According to WooCommerce, versions, 3.4.4 and earlier are affected by an issue where a function that updates attributes could lead to object injection, related to the WordPress 4.8.3 security release.","date":"2018-09-01"}],"impact":[]},{"uuid":"e752d999513d3d6d40ebb8956eebda3a8e839879b41525dc89b10f42fc9b5a15","name":"WooCommerce [woocommerce] < 3.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f6faa6785aacc0dfbb7e3981ee6d74ab9ec9f46a","name":"WordPress WooCommerce plugin <=3.2.3 - Authenticated PHP Object Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-3-2-3-authenticated-php-object-injection-vulnerability","description":"Authenticated PHP Object Injection vulnerability found in WordPress WooCommerce plugin (versions <=3.2.3).","date":"2018-02-23"}],"impact":[]},{"uuid":"833cfe6a8cdea92312c7b77aa009c0bb76e73710bdf82cf20f95d5530104768b","name":"WooCommerce [woocommerce] < 2.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b1b1e3352eb42153da0dd29d5b6707d8061bb32e","name":"WordPress WooCommerce Plugin <= 2.6.3 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-6-3-cross-site-scripting","description":"This plugin is prone to stored cross site scripting vulnerability via REST API.\nUpdate the plugin.","date":"2016-09-09"}],"impact":[]},{"uuid":"7e974298117480476817d54df3e056e833762d2dde97d4eaa6f2df643ae76141","name":"WooCommerce [woocommerce] < 2.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f53782e0528442b26d2e5c45e04bb136681afa7a","name":"WordPress WooCommerce Plugin <= 2.6.2 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-6-2-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2016-07-20"}],"impact":[]},{"uuid":"f1ee9f73da0d8e7c827dd0da39f186a2ae6482aff526a460fed36ddc266be5c8","name":"WooCommerce [woocommerce] < 2.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f4c49a0ee2d31ad566d2b0ed8897bdc9b93f2375","name":"WordPress WooCommerce Plugin <= 2.4.8 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-4-8-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-11-17"}],"impact":[]},{"uuid":"e39e6c16af671a4391c085dbaa18353073769ecf3923b691e09d0e81060dc11d","name":"WooCommerce [woocommerce] < 2.3.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5b2ca17949da7cb03cc0cc5b53a342109291a86a","name":"WordPress WooCommerce Plugin <= 2.3.10 - XXE","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-3-10-xxe","description":"This plugin has a PHP bug which allows to download critical files. Attacker can access to these files and compromise site.\nUpdate the plugin.","date":"2015-06-17"}],"impact":[]},{"uuid":"70b7611bf0c7d8dd4ded52ca6f516f9f0526e03c0ff1ae35e701ad86574fc9a3","name":"WooCommerce [woocommerce] < 2.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5fe4e02e4602ca1cad893a0b5dc7aa7e406d5397","name":"WordPress WooCommerce Plugin <= 2.1.12 - Reflected XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-1-12-reflected-xss","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-06-10"}],"impact":[]},{"uuid":"1db3331b446159e57ad2ae6a20bb4ef35ee89f8bd35e850c942c5c39827fbaf2","name":"WooCommerce [woocommerce] < 2.0.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f25e903f15df74bb85b2c464c4570f4f76adc511","name":"WordPress WooCommerce Plugin <= 2.0.17 - Reflected Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-0-17-reflected-cross-site-scripting","description":"his plugin is prone to a cross site scripting vulnerability via hide-wc-extensions-message parameter.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"7b8fc9e88eaeff16dd53ce535ac23682b57c7a311c752f857b012468f9091069","name":"WooCommerce [woocommerce] < 2.0.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1bc232658a1604c77b378ca30b3df17139be674e","name":"WordPress WooCommerce Plugin <= 2.0.12 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-0-12-cross-site-scripting","description":"This plugin is prone to a cross site scripting vulnerability via index.php calc_shipping_state parameter.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"9b466df1ce34cf21e5e8d3ce4d3fd307ff5d5862aac1884d94eccc9a9396b773","name":"WooCommerce [woocommerce] < 2.3.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0857b6b0161182ae366a0af377962535abbda70b","name":"WordPress WooCommerce Plugin <= 2.3.5 - SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-2-3-5-sql-injection","description":"Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"a2d63bd4471f96ca337db6ff9afdf598595838d7a3879db4213ea3fb860db0e3","name":"WooCommerce [woocommerce] < 6.6.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2099","name":"CVE-2022-2099","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2099","description":"[en] The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles","date":"2022-07-17"},{"id":"f97ede012999c00ee305844d687a4281b92cfccc","name":"WordPress WooCommerce plugin <= 6.5.1 - Authenticated Stored HTML Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-6-5-1-authenticated-stored-html-injection-vulnerability","description":"Authenticated Stored HTML Injection vulnerability discovered by Taurus Omar in WordPress WooCommerce plugin (versions <= 6.5.1).\nUpdate the WordPress WooCommerce plugin to the latest available version (at least 6.6.0).","date":"2022-06-20"},{"id":"423330ef385970308f57c58cd0df85af469b8b91","name":"WooCommerce <= 6.5.1 - Authenticated (Admin+) HTML Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-651-authenticated-admin-html-injection","description":"The WooCommerce plugin for WordPress is vulnerable to Stored HTML Injection via payment gateway titles in versions up to 6.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with high-level capabilities, such as a Store Manager, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-06-20"},{"id":"0316e5f3-3302-40e3-8ff4-be3423a3be7b","name":"WooCommerce < 6.6.0 - Admin+ Stored HTML Injection","link":"https:\/\/wpscan.com\/vulnerability\/0316e5f3-3302-40e3-8ff4-be3423a3be7b","description":"The plugin is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles","date":null}],"impact":{"cwe":[{"cwe":"CWE-116","name":"Improper Encoding or Escaping of Output","description":"The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved."}]}},{"uuid":"f53e350e5e88ea32dd71c0c6adc1f2d02c9731d874253df1a46fef590c4ab188","name":"WooCommerce [woocommerce] < 5.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3b50856e13c3ba90bb61eed52fe902192a1e7a96","name":"WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/woocommerce-570-woocommerce-admin-264-information-disclosure","description":"The WooCommerce and WooCommerce Admin plugins for WordPress are vulnerable to Sensitive Data Exposure in versions up to 5.7.0 for WooCommerce and 2.6.4 for WooCommerce Admin due to insufficient protection of analytic report storage in the directory they are stored. This makes it possible for attackers to extract sensitive data related to report analytics on certain host configurations.","date":"2022-04-10"}],"impact":[]},{"uuid":"2aa264f95467cc1d0721d3af4acc770b1a169d51bbea4dffed24682be67daf18","name":"WooCommerce [woocommerce] < 6.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ba4bccfa530a3ac6256a47136d3933ddc904b019","name":"WooCommerce < 6.3.1 - Unauthorized Order Status Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-631-unauthorized-order-status-change","description":"The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce check on the PayPal order updates functionality in versions up to, and including, 6.3.0. This makes it possible for authenticated attackers to change the status of arbitrary orders that have been created with PayPal.","date":"2022-03-10"}],"impact":[]},{"uuid":"4f8cf3d730a243182582fd7d83bda52f2fb6106243be5bae70e5e0d53628751c","name":"WooCommerce [woocommerce] < 6.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"373e4dc07c53895b3f6b848d829e17d55f724517","name":"WooCommerce <= 6.2.0 - Incorrect Authorization Checks on REST API Endpoints","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-620-incorrect-authorization-checks-on-rest-api-endpoints","description":"The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on the \/wc\/v2\/products\/ REST API in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers with minimal permissions such as a subscriber to delete, edit, and read arbitrary comments and reviews.","date":"2022-02-22"}],"impact":[]},{"uuid":"9cb7c43c75291726fe98dfefab5217ed75eb7134657cc392d12e770029eef9f6","name":"WooCommerce [woocommerce] < 6.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1fed8fc807d0643ef7ecc5918431bdb4c18661c6","name":"WooCommerce <= 6.2.0 - Path Traversal via Tax Importer","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-620-path-traversal-via-tax-importer","description":"The WooCommerce plugin for WordPress is vulnerable to path traversal via the 'file_url' parameter found in the importers functionality in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers, with high-level permissions such as an administrator, to access files outside of the intended directory when performing an import.","date":"2022-02-22"}],"impact":[]},{"uuid":"ef33e4c48593434a678e8bc022eb466eaf4a55ddd10dd7db92069fcdb26d353b","name":"WooCommerce [woocommerce] < 4.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7c89cd5e57fec6515bcfa76d45b6137ae3e03cad","name":"WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/woocommerce-461-woocommerce-blocks-370-settings-bypass-leading-to-account-creation","description":"The WooCommerce plugin for WordPress is vulnerable to unauthorized user account creation during checkout even when the \u201cAllow customers to create an account during checkout\u201d setting is disabled. was disabled due to missing authorization checks in versions up to and including 4.6.1. The WooCommerce Blocks plugin for WordPress is vulnerable to the same issue in versions up to, and including, 3.7.1.","date":"2020-11-05"}],"impact":[]},{"uuid":"f2795989d403e38443f9d27be7104a60848839b1f7d5b97f1db5477a18d696bd","name":"WooCommerce [woocommerce] < 4.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"80a68530774593703176012db68a7eac310bda11","name":"WooCommerce <= 4.2.0 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-420-reflected-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing sanitization and escaping in SelectWoo, that makes it possible for attackers to inject arbitrary web scripts. This affects versions up to 4.2.1.","date":"2020-06-22"}],"impact":[]},{"uuid":"96eee1589add88263fd531247ffd4b0f68b49acdb3c088daaea8c98f0e49019b","name":"WooCommerce [woocommerce] < 4.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"41f3a783e71e811a10a0fb89757b2dfb043d2f4d","name":"WooCommerce <= 4.0.4 - Unauthorized Post Meta Creation\/Modification","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-404-unauthorized-post-meta-creationmodification","description":"The WooCommerce plugin for WordPress is vulnerable to arbitrary product meta data creation\/overwriting due to \r\na lack of escaping and validation on the post meta data being supplied during product duplication in versions up to, and including 4.0.4. This makes it possible for authenticated attackers, with product duplicating capabilities, to modify post meta that could potential be used to achieve remote code execution.","date":"2020-05-05"}],"impact":[]},{"uuid":"8230d792f3eedd27d739bb426c69dda71b16bb239fdad21af98940ed90630116","name":"WooCommerce [woocommerce] < 3.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"900d393aa4a083f4816cf9d340f914404b688029","name":"WooCommerce <= 3.6.4 - Missing File Type Validation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-364-missing-file-type-validation","description":"The WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads via the tax rate importer due to missing file type validation that made it possible for high level authenticated attackers to upload malicious files in versions up to, and including, 3.6.4.","date":"2019-07-02"}],"impact":[]},{"uuid":"15af68f3cd595abc56da376f72e281a99b904fc1856a10b864b3960c1a4353c0","name":"WooCommerce [woocommerce] < 3.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"58c79829f3eccd7753727255a909ba97e7640f85","name":"WooCommerce <= 3.6.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-364-cross-site-request-forgery-to-stored-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 3.6.4, due to the CSV importer actions missing a nonce validation. This makes it possible for attackers with at least author privileges to embed script code in a CSV, upload it to the target site, and then trick an administrator into uploading the CSV injected payload to a product description via a forged request all granted they can trick them into performing an action such as clicking on a link.","date":"2019-07-02"}],"impact":[]},{"uuid":"c3dc76e07403ff6ceacbfc3b26e19d2fa525519811a1b1ec7a33ad6b55436277","name":"WooCommerce [woocommerce] < 3.5.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3893d977bae8486e98cea9c72c27da920233e509","name":"WooCommerce <= 3.5.1 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-351-authenticated-stored-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting due to sanitization and escaping on an unspecific variable, that makes it possible for attackers to inject arbitrary web scripts into pages. This affects versions up to 3.5.0, and can be exploited by users with write-access API keys.","date":"2018-11-29"}],"impact":[]},{"uuid":"48c496680d147200fff7ba3ddc33fd119eac5658c15d33b866f2d6b572dbc38c","name":"WooCommerce [woocommerce] < 3.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d4c98be7eeae0c6560670574afaf0aad8a9e2817","name":"WooCommerce <= 3.4.4 - Authenticated PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-344-authenticated-php-object-injection","description":"The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection by users with access to edit attributes in versions up to, and including 3.4.4.","date":"2018-08-29"}],"impact":[]},{"uuid":"15ae7f0fa7563d9a587b5fdc63a7684645803a8dd159a0aca7ce0528a456a042","name":"WooCommerce [woocommerce] < 2.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e21a13453469f19cac1eb7a7f766765bbc255e7a","name":"WooCommerce <= 2.6.3 - Stored Cross-Site Scripting via REST-API","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-263-stored-cross-site-scripting-via-rest-api","description":"The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image uploader feature powered by the \/wc-api\/v3\/products\/categories\/ REST-API in versions up to, and including, 2.6.3 due to insufficient filetype validation. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2016-07-26"}],"impact":[]},{"uuid":"412b3bf50cb5ede0417590730c3216cb50badcba256476f44c12ef64e6af34a3","name":"WooCommerce [woocommerce] < 2.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"009a2c2d6d4a280f240576221c6d9c7773b1334a","name":"WooCommerce <= 2.6.2 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-262-stored-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image EXIF metadata in versions up to, and including, 2.6.2 due to insufficient validation on image files EXIF content. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2016-07-19"}],"impact":[]},{"uuid":"7b8425b13fd730fc6d0a38897fc96435fc04e776680230500e53aede29961b51","name":"WooCommerce [woocommerce] < 2.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"25cd2e5224ceb8e144c3f04665cc2bf060a3e253","name":"WooCommerce < 2.4.9 - Cross-site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-249-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the pay_price() function, in versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2015-11-17"}],"impact":[]},{"uuid":"817fb71f530f871a40e7450d60b02f07bf11e01917e503fb2cff8831e3c74895","name":"WooCommerce [woocommerce] >= 2.0.20 – <= 2.3.10","description":null,"operator":{"min_version":"2.0.20","min_operator":"ge","max_version":"2.3.10","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"cc5950d49d73a8fb839b4f068605db20a073f9f6","name":"WooCommerce <= 2.3.10 - PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-2310-php-object-injection","description":"The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.10 via deserialization of untrusted input from the $custom parameter. This allows authenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to exploit XXE and read sensitive files from the server.","date":"2015-06-10"}],"impact":[]},{"uuid":"6db3665fc02c5c2d4b97a78889d62e4cd51ddc369cd5da60f3c11cc2be0b7aba","name":"WooCommerce [woocommerce] < 2.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dc9f67fb79cd640b3af080a3e4fdab2178e4d99b","name":"WooCommerce <= 2.2.2 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-222-reflected-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2014-09-17"}],"impact":[]},{"uuid":"20ffe6a13ba67ec176daf0b09f1f377b44e5846a0743aa17cea3659d299a1f02","name":"WooCommerce [woocommerce] < 2.0.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"09ab0bd00e389d9747bae64db77b44ca10248598","name":"WooCommerce <= 2.0.17 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-2017-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.17 via the 'hide-wc-extensions-message' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser session.","date":"2013-10-17"}],"impact":[]},{"uuid":"9d3e98f921afffdc1b55d8c68404570e43b5a9a72cc5da3ffbad6646a8a83272","name":"WooCommerce [woocommerce] < 2.0.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"29ec75461f36da3f29ade02f2341bf0adfbb5d3c","name":"WooCommerce <= 2.0.12 - Self-Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-2012-self-reflected-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Self-Reflected Cross-Site Scripting in versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2013-07-18"}],"impact":[]},{"uuid":"21f05b2f3f6994e5890658d591879dfb3ed8ccc8b5924acbd79984f37345e65e","name":"WooCommerce [woocommerce] < 2.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a2cc949c-838f-4e47-9ee8-07e3fb3cb049","name":"WooCommerce <= 2.1.12 - Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/a2cc949c-838f-4e47-9ee8-07e3fb3cb049","description":"The WooCommerce WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"55e81b2943e203a5ef6aec5a0b5481585878cb05c24649c8f5b6fec315332c14","name":"WooCommerce [woocommerce] < 2.0.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"05600919-3d11-4539-8850-3ac8fc6fe5a9","name":"WooCommerce 2.0.12 - index.php calc_shipping_state Parameter XSS","link":"https:\/\/wpscan.com\/vulnerability\/05600919-3d11-4539-8850-3ac8fc6fe5a9","description":"The WooCommerce WordPress plugin was affected by an index.php calc_shipping_state Parameter XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"d452967c61310487df210534aad2f80b1996f6c596fdadd4d156079da938416c","name":"WooCommerce [woocommerce] < 2.0.17","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.17","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6f59b2c9-1466-4c83-8967-cc1bb9b07ea6","name":"WooCommerce 2.0.17 - hide-wc-extensions-message Parameter Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/6f59b2c9-1466-4c83-8967-cc1bb9b07ea6","description":"The WooCommerce WordPress plugin was affected by a hide-wc-extensions-message Parameter Reflected XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"5fc488a0bdbecbd1b80a61e230dd8d91e3e0a6a06c8aa2a18c8a0db40cae4c18","name":"WooCommerce [woocommerce] < 6.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bdda03d0-d657-4e12-8996-40152194c607","name":"WooCommerce < 6.3.1 - Orders Marked as Paid (via PayPal Standard Gateway)","link":"https:\/\/wpscan.com\/vulnerability\/bdda03d0-d657-4e12-8996-40152194c607","description":"The PayPal Standard payment gateway (deprecated since July 2021) of the plugin could allow attackers to mark an order as paid without actually making a payment, when PDT is enabled.","date":null}],"impact":[]},{"uuid":"d868217e2ff41e14fea6f2827efebd5ced7d54c9b390fb3abdc5f8f8d1e016cb","name":"WooCommerce [woocommerce] < 5.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"26e169da-4020-4b3d-8bee-af01bd853791","name":"WooCommerce < 6.2.1 - Path Traversal via Importers","link":"https:\/\/wpscan.com\/vulnerability\/26e169da-4020-4b3d-8bee-af01bd853791","description":"The plugin does not properly check for path traversal when importing tax rates. There are limited details at this stage and this advisory will be updated later on","date":null}],"impact":[]},{"uuid":"23c13a7e66e92b60f3dee3fbff4daa81317b8d7d211cd81144d51cc6177f5120","name":"WooCommerce [woocommerce] < 6.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0775","name":"CVE-2022-0775","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0775","description":"[en] The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment","date":"2024-01-16"},{"id":"b76dbf37-a0a2-48cf-bd85-3ebbc2f394dd","name":"WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion","link":"https:\/\/wpscan.com\/vulnerability\/b76dbf37-a0a2-48cf-bd85-3ebbc2f394dd","description":"The plugin does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment","date":null}],"impact":{"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}]}},{"uuid":"fd300bc8c208bfddc1151308a0a0bd6766c5461630f319110f9ded466bd3cac1","name":"WooCommerce [woocommerce] < 5.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6f1ecd1e-5363-44df-b9c7-a67dc9398261","name":"WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Analytics Report Leaks","link":"https:\/\/wpscan.com\/vulnerability\/6f1ecd1e-5363-44df-b9c7-a67dc9398261","description":"The plugin was vulnerable to Analytics Report Leaks on some hosting configurations.\r\n\r\nAs well as updating WooCommerce to at least version 5.7.0, and WooCommerce Admin to at least version 2.6.4, it is also recommended that directory listing is disabled on your host.\r\n\r\nAutomattic updates were rolled out to force the vulnerable plugins to be updated and patched.","date":null}],"impact":[]},{"uuid":"30d3487383b3861ffa2ad0a677be1f04768b3964446dd065cdd66d8d77de4d77","name":"WooCommerce [woocommerce] < 4.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3f3094ed-23ea-4bfb-847a-d06d8a7e7cee","name":"WooCommerce < 4.6.2 - Guest Account Creation","link":"https:\/\/wpscan.com\/vulnerability\/3f3094ed-23ea-4bfb-847a-d06d8a7e7cee","description":"Versions of WooCommerce prior to 4.6.2 contain a vulnerability that allows guest users to create accounts during checkout even when the "Allow customers to create an account during checkout" setting is disabled. This vulnerability is being exploited by a bot to place spam orders and create user accounts that are then used to probe for vulnerabilities in other plugins on the site.","date":null}],"impact":[]},{"uuid":"ca49a46c35fac88c981ee8e693323ec72d38db94ce45add2a735d4d5fd5e4ab8","name":"WooCommerce [woocommerce] < 4.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8dac6eec-6573-4de0-b37f-ff09834c50bd","name":"WooCommerce < 4.2.1 - Potential Cross-Site Scripting (XSS) via SelectWoo","link":"https:\/\/wpscan.com\/vulnerability\/8dac6eec-6573-4de0-b37f-ff09834c50bd","description":"A DOM based Cross-Site Scripting (XSS) vulnerability was found to affect the SelectWoo dependency that WooCommerce used. SelectWoo replaces the standard <select> box in web browsers.","date":null}],"impact":[]},{"uuid":"5fa3a12c37a0ee11be50dddde9b23e60912c1b84aa3b3e612510b26eef6f46b5","name":"WooCommerce [woocommerce] < 4.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e938f544-d043-4831-888f-52d94e7c6c3d","name":"WooCommerce < 4.1.0 - Unescaped Metadata when Duplicating Products","link":"https:\/\/wpscan.com\/vulnerability\/e938f544-d043-4831-888f-52d94e7c6c3d","description":"The WooCommerce changelog file was updated with the following message:\r\n\r\n"Security – Fixed unescaped meta data while duplicating products. Reported by Slavco."\r\n\r\nWe will update this issue with further information as it becomes available.","date":null}],"impact":[]},{"uuid":"456c73727fc1c6bb58214d0d03b47fd6ebf17cc4f8de96eec614f5ec37429a50","name":"WooCommerce [woocommerce] < 3.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4760a717-3f2d-4491-bfb1-ae0754c3bda5","name":"WooCommerce <= 3.6.4 - Cross-Site Request Forgery (CSRF) & File Type Check","link":"https:\/\/wpscan.com\/vulnerability\/4760a717-3f2d-4491-bfb1-ae0754c3bda5","description":"Changelog mentions:\r\n\r\nSecurity – Introduce file type check for tax rate importer.\r\nSecurity – Added nonce check to CSV importer actions.\r\n\r\nRIPS Tech later released an advisory detailing the vulnerability, which can be found in the references.","date":null}],"impact":[]},{"uuid":"e60538ec69083dc1b4eb4cb9dccaa226afae269a6d0ec10101ff35b7e4c4de8f","name":"WooCommerce [woocommerce] < 3.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"446d5271-c32a-4298-be0d-8e2f60681a71","name":"WooCommerce <= 3.5.0 - Authenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/446d5271-c32a-4298-be0d-8e2f60681a71","description":"The WooCommerce WordPress plugin was affected by an Authenticated Stored XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"58ef90f442766e793c93c14aa57f062162a253c48bab2f50607ab57df190bb91","name":"WooCommerce [woocommerce] < 3.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9567f575-529d-4d66-980c-73cba6726673","name":"WooCommerce <= 3.4.5 - Authenticated Phar Deserialization","link":"https:\/\/wpscan.com\/vulnerability\/9567f575-529d-4d66-980c-73cba6726673","description":"The WooCommerce WordPress plugin was affected by an Authenticated Phar Deserialization security vulnerability.","date":null}],"impact":[]},{"uuid":"a034f6661bd13e16ccf341b3b9a2fe1ecd73d3830872792aa0cd9343ce6ded30","name":"WooCommerce [woocommerce] < 3.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7275a176-d579-471a-8492-df8edbdf27de","name":"WooCommerce <= 3.4.5 - Authenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/7275a176-d579-471a-8492-df8edbdf27de","description":"The WooCommerce WordPress plugin was affected by an Authenticated Stored XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"0189d255e39ee8bc0f3e69ea470eeee6c5017b224954687efb03044e030c9260","name":"WooCommerce [woocommerce] < 3.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b9af34f0-9012-41a1-870b-89d4e5d2eb27","name":"WooCommerce <= 3.4.5 - Authenticated Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/b9af34f0-9012-41a1-870b-89d4e5d2eb27","description":"According to WooCommerce:\r\n\r\n"Versions 3.4.5 and earlier are affected by a handful of issues that allow Shop Managers to exceed their capabilities and perform malicious actions. These issues can be exploited by users with Shop Manager capabilities or greater, and we recommend all users running WooCommerce 3.x upgrade to 3.4.6 to mitigate them. Thanks to Simon Scannell, Karim, and Slavco for reporting the issues."\r\n\r\nSee references for PoC and further technical details.","date":null}],"impact":[]},{"uuid":"5ec678a9a92465923e6bd2288516bff6ac21ae2ac5abc64e966a7a8c34bb8910","name":"WooCommerce [woocommerce] < 3.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"13a534b4-97bd-48e1-b936-cc57c9c56396","name":"WooCommerce <= 3.4.4 - Potential Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/13a534b4-97bd-48e1-b936-cc57c9c56396","description":"According to WooCommerce:\r\n\r\n"Versions 3.4.4 and earlier are affected by an issue where a function that updates attributes could lead to object injection. This is related to the WordPress 4.8.3 security release.\r\n\r\nThis issue can only be exploited by users who can edit attributes and should not be possible to exploit through the WordPress administrative screens, but we still recommend all users running WooCommerce 3.x upgrade to 3.4.5 to mitigate this issue. Thanks to slavco for responsibly disclosing the vulnerability to us."","date":null}],"impact":[]},{"uuid":"b02b43e6cd6e650865ffc46fb5e38b8387e502db266651354e17c46cc3b6aaeb","name":"WooCommerce [woocommerce] < 2.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d4f7dff0-7391-4448-95dd-327f0803a9b8","name":"WooCommerce <= 2.6.3 - Stored Cross Site Scripting (XSS) via REST API","link":"https:\/\/wpscan.com\/vulnerability\/d4f7dff0-7391-4448-95dd-327f0803a9b8","description":"The WooCommerce WordPress plugin was affected by a Stored Cross Site Scripting (XSS) via REST API security vulnerability.","date":null}],"impact":[]},{"uuid":"11f1f444682d4de020bbc4727b992a3b6cbc54f6736f7d971147c5c29f303ec1","name":"WooCommerce [woocommerce] < 2.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b0761276-0a27-4a9b-96ff-faf751a5e77a","name":"WooCommerce <= 2.4.8 - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/b0761276-0a27-4a9b-96ff-faf751a5e77a","description":"The WooCommerce WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"0a4c7732740c1fee95a89ecd22bb56101beef13cfeab1fcfd46c01983becd5e0","name":"WooCommerce [woocommerce] < 2.3.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9d4d6f49-5e02-4424-860e-f41453c9d7cf","name":"WooCommerce 2.0.20-2.3.10 - Object Injection \/ XXE","link":"https:\/\/wpscan.com\/vulnerability\/9d4d6f49-5e02-4424-860e-f41453c9d7cf","description":"According to the researcher: The vulnerability is only present when WooCommerce’s "PayPal Identity Token" option is set.","date":null}],"impact":[]},{"uuid":"49d9fde1de3a959c33902c9c114c4cc59515ef3315feb3e7d522943064d150bb","name":"WooCommerce [woocommerce] < 2.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"39988889-a8f4-4434-a9e9-598f926cf0b0","name":"WooCommerce <= 2.6.2 - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/39988889-a8f4-4434-a9e9-598f926cf0b0","description":"The WooCommerce WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"dad0462eb59203497fb7d312b6fdf52f791017da01ce7757d78a4a9d85548955","name":"WooCommerce [woocommerce] < 7.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"16b2bce4324d02147ad3d27b2c123adf5207626d","name":"WooCommerce <= 7.0.0 - Authenticated(Shop Manager+) Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-700-authenticatedshop-manager-sensitive-information-exposure","description":"The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.0. This can allow authenticated attackers with Shop Manager privileges or above to extract sensitive user metadata including session tokens.","date":"2023-09-11"}],"impact":[]},{"uuid":"8b5ff6bece961dce5b443914e4a8077f8ca08df2b5584e0fa7b5bf38ae0b1f55","name":"WooCommerce [woocommerce] < 7.9.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"129632aede1886afc5c1c92626e2b0cf79dcda18","name":"WooCommerce <= 7.8.2 - Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-782-sensitive-information-exposure","description":"The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information including PII(Personal Identifiable Information).","date":"2023-09-11"}],"impact":[]},{"uuid":"3bb7ada696adf9ad1f94cfb1c2865825a5411fdde221d65c7e67bf48d9385b73","name":"WooCommerce [woocommerce] < 7.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bb9f355a-be33-41b1-af36-0a30c24bec8c","name":"WooCommerce < 7.0.1 - Shop Manager+ User Metadata Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/bb9f355a-be33-41b1-af36-0a30c24bec8c","description":"The plugin returns all user metadata via an AJAX action, which could allow users with a role as low as Shop Manager to access an arbitrary user's metadata which could include tokens and other potentially sensitive data","date":null}],"impact":[]},{"uuid":"2878efe2a9926c60183d0132f13590d0f6fae0e5b8f8b9e06cf2e614f8635787","name":"WooCommerce [woocommerce] < 7.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d1cec296-b5df-4cea-8c0d-d03a975cb6af","name":"WooCommerce < 7.9 - Unauthenticated Sensitive Information Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/d1cec296-b5df-4cea-8c0d-d03a975cb6af","description":"The plugin does not properly apply CORS on some of its API endpoints, allowing attackers to leak customers PII information.","date":null}],"impact":[]},{"uuid":"1edabdb8526941ada1c2385a827552709737de7ddbfad3e80fce5e27008aab12","name":"WooCommerce [woocommerce] < 8.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47777","name":"CVE-2023-47777","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47777","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n\/a through 8.1.1; WooCommerce Blocks: from n\/a through 11.1.1.","date":"2023-11-30"},{"id":"65323e6368e860c62d4e1a7edfce87ff78dbe4de","name":"WordPress WooCommerce Plugin <= 8.1.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-8-1-1-contributor-cross-site-scripting-xss-vulnerability","description":"Update the WordPress WooCommerce plugin to the latest available version (at least 8.2.0).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WooCommerce Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 8.2.0.","date":"2023-11-15"},{"id":"febfcef745aa65c4579429558a49187421b67afe","name":"WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image alt Attribute","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/woocommerce-811-woocommerce-blocks-1111-authenticated-contributor-stored-cross-site-scripting-via-featured-image-alt-attribute","description":"The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a featured image 'alt' attribute in versions up to, and including, 8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The WooCommerce Blocks plugin for WordPress is vulnerable to the same issue in versions up to, and including, 11.1.1.","date":"2023-11-15"},{"id":"b8e9b8cf-8d13-4fd8-8e1e-ee35a01baf05","name":"WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image alt Attribute","link":"https:\/\/wpscan.com\/vulnerability\/b8e9b8cf-8d13-4fd8-8e1e-ee35a01baf05","description":"The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a featured image 'alt' attribute in versions up to, and including, 8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The WooCommerce Blocks plugin for WordPress is vulnerable to the same issue in versions up to, and including, 11.1.1.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"5b2f6f5df1b5efe2624430ab221f6ddcaa4cf2dd089923cca59e6de19c481fac","name":"WooCommerce [woocommerce] < 7.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"45f56af8-b238-41a5-b7d5-bd40982d5ed7","name":"WooCommerce < 7.0.1 - Authenticated(Shop Manager+) Sensitive Information Exposure","link":"https:\/\/wpscan.com\/vulnerability\/45f56af8-b238-41a5-b7d5-bd40982d5ed7","description":"The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.0. This can allow authenticated attackers with Shop Manager privileges or above to extract sensitive user metadata including session tokens.","date":null}],"impact":[]},{"uuid":"dc33e5193a37d23dc622c1b24cc35ee465c7aeea09827963a19d943919bf5eca","name":"WooCommerce [woocommerce] < 7.9.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9c9498b0-d42e-4ce0-b299-ba5d08058a75","name":"WooCommerce < 7.9.0 - Sensitive Information Exposure","link":"https:\/\/wpscan.com\/vulnerability\/9c9498b0-d42e-4ce0-b299-ba5d08058a75","description":"The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information including PII(Personal Identifiable Information).","date":null}],"impact":[]},{"uuid":"6e9a2e5e94d80b516fe3d1565872aece7ad56ba8e15ebd22dca0f99b95b75f34","name":"WooCommerce [woocommerce] < 8.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-52222","name":"CVE-2023-52222","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-52222","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n\/a through 8.2.2.","date":"2024-01-08"},{"id":"80c03f1c938096e5f871a13f5b637d0bab0a165e","name":"WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-8-2-2-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress WooCommerce plugin to the latest available version (at least 8.3.0).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WooCommerce Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 8.3.0.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-05"},{"id":"26c0a67d96a07c3774b1f6632df09fc67f9cfc77","name":"WooCommerce <= 8.2.2 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-822-cross-site-request-forgery","description":"The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-01-05"},{"id":"d11e7996-3417-4b1b-a090-2f4d31cdd11d","name":"WooCommerce < 8.3.0 - Cross-Site Request Forgery","link":"https:\/\/wpscan.com\/vulnerability\/d11e7996-3417-4b1b-a090-2f4d31cdd11d","description":"The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"95e6a6f56398dc3be1fd137c3cde05dc08c63038ebbac1c6efed83272e9942eb","name":"WooCommerce [woocommerce] < 8.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bb053f3c24afaa2cf4bc50ebf0e88d8b6f601d08","name":"WooCommerce < 8.4.0 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-840-reflected-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions before 8.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. IMPORTANT: There was a miscommunication and error in this vulnerability record where we initially reported version 8.5.0 as patched, while 8.4.0 was still vulnerable. This issue was patched in version 8.4.0 and only affects versions up to 8.3.0. Please rest assured knowing you can update the plugin to version 8.4.0 and this issue will be patched.","date":"2024-01-12"}],"impact":[]},{"uuid":"de853b94d24719ab207b853c5c6a3a9222ce23d370c4b6b9c4003d0aca2dd4c0","name":"WooCommerce [woocommerce] < 8.6.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.6.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-22155","name":"CVE-2024-22155","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-22155","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n\/a through 8.5.2.","date":"2024-04-07"},{"id":"ae1cdde8b4215a77b038719fe9c2957eb3b1c6e6","name":"WordPress WooCommerce Plugin <= 8.5.2 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-8-5-2-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress WooCommerce plugin to the latest available version (at least 8.6.0).\nDhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WooCommerce Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 8.6.0.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"a63473d6c730d10cf4fa7646f030f6bfef58982a","name":"WooCommerce <= 8.5.2 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-852-cross-site-request-forgery","description":"The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-04-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"d465b504323a52466b3bf55b4898342a321a37ebf724d11dd4a02966b34f38a8","name":"WooCommerce [woocommerce] < 8.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"49c085a4182d94ecc142c402c76481462b949a87","name":"WordPress WooCommerce Plugin <= 8.3.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-8-3-0-reflected-cross-site-scripting-vulnerability","description":"Update the WordPress WooCommerce plugin to the latest available version (at least 8.4.0).\nAn unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WooCommerce Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 8.4.0.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":[]},{"uuid":"cfda4a5ef523763eedda3978b1921563df7ec33b4bafc14e7db5df2d4662ec32","name":"WooCommerce [woocommerce] < 8.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1310","name":"CVE-2024-1310","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1310","description":"[en] The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)","date":"2024-04-15"},{"id":"228248d7df40ac55f0a73aff056a12567e722474","name":"WordPress WooCommerce Plugin < 8.6 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-8-6-contributor-private-draft-products-access-vulnerability","description":"

WordPress WooCommerce Plugin < 8.6 is vulnerable to Broken Access Control<\/p>

Software: WooCommerce<\/p>

Link: https:\/\/wordpress.org\/plugins\/woocommerce\/#developers<\/p>

Affected Version < 8.6<\/p>

Fixed in version 8.6 <\/p>“,”date”:”2024-04-15″},{“id”:”4b297efe5597c7a73c0ec250a35cf6599b7692b2″,”name”:”WooCommerce <= 8.5.2 - Missing Authorization to Private\/Draft Product Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/post-new\/woocommerce-852-missing-authorization-to-privatedraft-product-disclosure","description":"The WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to insufficient restrictions in the product shortcode in all versions up to, and including, 8.5.2. This makes it possible for authenticated attackers, with contributor-level access and above, to view private and draft products.","date":"2024-03-25"},{"id":"a7735feb-876e-461c-9a56-ea6067faf277","name":"WooCommerce < 8.6 - Contributor+ Private\/Draft Products Access","link":"https:\/\/wpscan.com\/vulnerability\/a7735feb-876e-461c-9a56-ea6067faf277","description":"The plugin does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)","date":null}],"impact":{"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}]}},{"uuid":"a4fb4d8390206c5c360657ced202b1e75af3fee4cf3d5a064e98335f15ff6d03","name":"WooCommerce [woocommerce] < 8.9.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.9.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5619e13f0d284b547a86dfa0340848e80577103b","name":"WordPress WooCommerce Plugin <= 8.9.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-8-9-2-reflected-cross-site-scripting-xss-vulnerability","description":"

WordPress WooCommerce Plugin <= 8.9.2 is vulnerable to Cross Site Scripting (XSS)<\/p>

Software: WooCommerce<\/p>

Link: https:\/\/wordpress.org\/plugins\/woocommerce\/#developers<\/p>

Affected Version <= 8.9.2<\/p>

Fixed in version 8.9.3 <\/p>“,”date”:”2024-06-11″}],”impact”:[]},{“uuid”:”7eae8f2742e8151d904a0d4b03f6a72aec9db194243fbc4b04035eea5b2e390c”,”name”:”WooCommerce [woocommerce] < 8.9.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.9.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-37297","name":"CVE-2024-37297","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-37297","description":"[en] WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While the content is not saved to the database, the links may be sent to victims for malicious purposes. The injected JavaScript could hijack content & data stored in the browser, including the session. The URL content is read through the `Sourcebuster.js` library and then inserted without proper sanitization to the classic checkout and registration forms. Versions 8.8.5 and 8.9.3 contain a patch for the issue. As a workaround, one may disable the Order Attribution feature.","date":"2024-06-12"},{"id":"79cce02de9a42b619dd87f969ca5c5c811e3ae13","name":"WooCommerce 8.8.0 - 8.9.2 - Reflected Cross-Site Scripting via Order Attribution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-880-892-reflected-cross-site-scripting-via-order-attribution","description":"The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via order attribution cookies in versions 8.8.0 to 8.8.4 and 8.9.0 to 8.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-06-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\”, and \”&\” that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.”}]}},{“uuid”:”ebdd6d290aacbf765e4b9033bf1db7b12a869ff6126713cdb7d7529badef8541″,”name”:”WooCommerce [woocommerce] < 9.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-35777","name":"CVE-2024-35777","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-35777","description":"[en] Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n\/a through 8.9.2.","date":"2024-07-09"},{"id":"73f7a28ac3f4297d0de641fab9e24bbcbf221dfa","name":"WordPress WooCommerce Plugin <= 8.9.2 is vulnerable to Content Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-8-9-2-content-injection-vulnerability","description":"

WordPress WooCommerce Plugin <= 8.9.2 is vulnerable to Content Injection<\/p>

Software: WooCommerce<\/p>

Link: https:\/\/wordpress.org\/plugins\/woocommerce\/#developers<\/p>

Affected Version <= 8.9.2<\/p>

Fixed in version 9.0.0 <\/p>“,”date”:”2024-06-27″},{“id”:”1fe0cb1a8cfbb5cfc0eca70317eb868ac0c26c1b”,”name”:”WooCommerce <= 8.9.2 - Authenticated (Shop Manager+) Content Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-892-authenticated-shop-manager-content-injection","description":"The WooCommerce plugin for WordPress is vulnerable to content injection in all versions up to, and including, 8.9.2. This is due to the plugin not properly restricting\/validating content. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inject arbitrary content.","date":"2024-06-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"3.5","severity":"l","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."}]}},{"uuid":"a017173dac82754443b91ebeca9932ee87f63118f362a82cef0d7d15998e61e7","name":"WooCommerce [woocommerce] < 8.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0b51f01a-24d9-4101-bdcf-728b21efc5ed","name":"WooCommerce < 8.4.0 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/0b51f01a-24d9-4101-bdcf-728b21efc5ed","description":"The plugin does not properly sanitize user-input provided by the add_query_arg() function when echoed back into JavaScript code context.","date":null}],"impact":[]},{"uuid":"c8a051e80651bec9479292c367e2ae288216dadd8698094d8eaeb5d102b33019","name":"WooCommerce [woocommerce] < 9.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-39666","name":"CVE-2024-39666","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-39666","description":"[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n\/a through 9.1.2.","date":"2024-08-18"},{"id":"605381f9b467c47b52c3742c74cf05c77353558e","name":"WordPress WooCommerce Plugin <= 9.1.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-9-1-2-cross-site-scripting-xss-vulnerability","description":"

WordPress WooCommerce Plugin <= 9.1.2 is vulnerable to Cross Site Scripting (XSS)<\/p>

Software: WooCommerce<\/p>

Link: https:\/\/wordpress.org\/plugins\/woocommerce\/#developers<\/p>

Affected Version <= 9.1.2<\/p>

Fixed in version 9.1.3 <\/p>“,”date”:”2024-08-16″},{“id”:”6e4e0203023ddd97c1bd50f57d9b0fe97b074c9b”,”name”:”WooCommerce <= 9.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-912-authenticated-administrator-stored-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-08-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"92f53061ceec12582138e794cb82827595014c3f87ce50a3ef62bb067514974a","name":"WooCommerce [woocommerce] < 9.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-9944","name":"CVE-2024-9944","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-9944","description":"[en] The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.","date":"2024-10-15"},{"id":"d8b711805a9dfe360f8b720f52482cccf27f87c3","name":"WordPress WooCommerce Plugin <= 9.0.2 is vulnerable to Content Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-9-0-2-unauthenticated-html-injection-vulnerability","description":"

WordPress WooCommerce Plugin <= 9.0.2 is vulnerable to Content Injection<\/p>

Software: WooCommerce<\/p>

Link: https:\/\/wordpress.org\/plugins\/woocommerce\/#developers<\/p>

Affected Version <= 9.0.2<\/p>

Fixed in version 9.1.0 <\/p>“,”date”:”2024-10-15″},{“id”:”4239301652b1e46a89171bf2524407b8c815e165″,”name”:”WooCommerce <= 9.0.2 - Unauthenticated HTML Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-902-unauthenticated-html-injection","description":"The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.","date":"2024-10-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"c5798f3828bb9462bc21a8267386ec6981f6eb3ac74a89de49bdaae2aa360d18","name":"WooCommerce [woocommerce] < 9.4.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.4.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d448b9d0999c662b17a6b5ecdc1b92699265a68c","name":"WordPress WooCommerce Plugin < 9.4.3 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce\/vulnerability\/wordpress-woocommerce-plugin-9-4-3-unauthenticated-order-creation-vulnerability","description":"

WordPress WooCommerce Plugin < 9.4.3 is vulnerable to Broken Access Control<\/p>

Software: WooCommerce<\/p>

Fixed in version 9.4.3 <\/p>

Affected Version < 9.4.3<\/p>“,”date”:”2024-12-04″}],”impact”:[]},{“uuid”:”c3df47dd2956a47ee882fe16bb26ce1d6352d64d83307fb5e4644628d36321da”,”name”:”WooCommerce [woocommerce] < 9.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-26762","name":"CVE-2025-26762","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-26762","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce allows Stored XSS.This issue affects WooCommerce: from n\/a through 9.7.0.","date":"2025-03-27"},{"id":"2285bab16f972ec527c65c72d9de3b2d29a8da6b","name":"WooCommerce <= 9.7.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-970-authenticated-shop-manager-stored-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"80a20c0ecbcc72ac693a9209561d33defc153ec7b74f76bc950f4b59311df74f","name":"WooCommerce [woocommerce] <= 9.4.2 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.4.2","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2025-5062","name":"CVE-2025-5062","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-5062","description":"","date":null},{"id":"69059aa88486ba382aa0177485fdcf8abcd76210","name":"WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce\/woocommerce-942-postmessage-based-cross-site-scripting","description":"The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":null},{"id":"EUVD-2025-16105","name":"EUVD-2025-16105","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-16105","description":"The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2025-05-22"}],"impact":[]},{"uuid":"8cf50dbea811649e583f057323e5a3edb5bdc8771249d4708379b77dc2ab705e","name":"WooCommerce [woocommerce] <= 10.0.2 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.0.2","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2025-49042","name":"CVE-2025-49042","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-49042","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n\/a through 10.0.2.","date":"2025-10-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}}]},"updated":"1761804867"}