online business security
WooCommerce Vulnerability – Reflected Cross-Site Scripting via Order Attribution – CVE-2024-37297 | WordPress Plugin Vulnerability Report
Plugin Name: WooCommerce Key Information: Software Type: Plugin Software Slug: woocommerce Software Status: Active Software Author: woothemes Software Downloads: 317,169,418 Active Installs: 7,000,000 Last Updated: June 20, 2024 Patched Versions: 8.8.5, 8.9.3 Affected Versions: 8.8.0 – 8.8.4, 8.9.0 – 8.9.2 Vulnerability Details: Name: WooCommerce 8.8.0 – 8.9.2 Title: Reflected Cross-Site Scripting via Order Attribution Type:…
Read MoreWooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Vulnerability – Missing Authorization to Unauthenticated Settings Reset – CVE-2024-3216 | WordPress Plugin Vulnerability Report
Plugin Name: WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Key Information: Software Type: Plugin Software Slug: print-invoices-packing-slip-labels-for-woocommerce Software Status: Active Software Author: webtoffee Software Downloads: 1,383,697 Active Installs: 50,000 Last Updated: April 8, 2024 Patched Versions: 4.4.3 Affected Versions: <= 4.4.2 Vulnerability Details: Name: WooCommerce PDF Invoices, Packing Slips, Delivery Notes and…
Read MoreWP-Members Membership Plugin Vulnerability – Unauthenticated Stored Cross-Site Scripting – CVE-2024-1852 | WordPress Plugin Vulnerability Report
Plugin Name: WP-Members Membership Plugin Key Information: Software Type: Plugin Software Slug: wp-members Software Status: Active Software Author: cbutlerjr Software Downloads: 3,453,636 Active Installs: 60,000 Last Updated: April 1, 2024 Patched Versions: 3.4.9.3 Affected Versions: <= 3.4.9.2 Vulnerability Details: Name: WP-Members Membership Plugin <= 3.4.9.2 Title: Unauthenticated Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-1852 CVSS…
Read MoreWooCommerce Vulnerability – Reflected Cross-Site Scripting | WordPress Plugin Vulnerability Report
Plugin Name: WooCommerce Key Information: Software Type: Plugin Software Slug: woocommerce Software Status: Active Software Author: woothemes Software Downloads: 289,194,192 Active Installs: 5,000,000 Last Updated: January 12, 2024 Patched Versions: 8.4.0 Affected Versions: < 8.4.0 Vulnerability Details: Name: WooCommerce < 8.4.0 Title: Reflected Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE: NA CVSS Score: 6.1 Publicly Published: January…
Read More