WooCommerce update

WooCommerce Vulnerability – Authenticated (Shop Manager+) Content Injection – CVE-2024-35777 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jun 27, 2024

Plugin Name: WooCommerce Key Information: Software Type: Plugin Software Status: Active Software Author: woocommerce Software Downloads: 322,936,863 Active Installs: 7,000,000 Last Updated: July 11, 2024 Patched Versions: 9.0.0 Affected Versions: <= 8.9.2 Vulnerability Details: Name: WooCommerce <= 8.9.2 Title: Authenticated (Shop Manager+) Content Injection Type: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N CVE: CVE-2024-35777 CVSS Score: 2.7 Publicly Published: June 27,…

Read More

WooCommerce Vulnerability – Reflected Cross-Site Scripting via Order Attribution – CVE-2024-37297 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jun 10, 2024

Plugin Name: WooCommerce Key Information: Software Type: Plugin Software Slug: woocommerce Software Status: Active Software Author: woothemes Software Downloads: 317,169,418 Active Installs: 7,000,000 Last Updated: June 20, 2024 Patched Versions: 8.8.5, 8.9.3 Affected Versions: 8.8.0 – 8.8.4, 8.9.0 – 8.9.2 Vulnerability Details: Name: WooCommerce 8.8.0 – 8.9.2 Title: Reflected Cross-Site Scripting via Order Attribution Type:…

Read More