Lucene search

K

Storeapps Security Vulnerabilities

cve
cve

CVE-2021-24836

The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them

4.3CVSS

4.6AI Score

0.001EPSS

2021-12-13 11:15 AM
19
4
cve
cve

CVE-2021-34619

The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.

8.8CVSS

8.6AI Score

0.002EPSS

2021-07-21 03:16 PM
23
2
cve
cve

CVE-2022-25649

Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.

8.8CVSS

8.8AI Score

0.001EPSS

2022-08-05 04:15 PM
40
3
cve
cve

CVE-2022-36284

Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile page.

6.5CVSS

6.3AI Score

0.001EPSS

2022-08-05 04:15 PM
40
4
cve
cve

CVE-2022-40694

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress.

4.8CVSS

4.8AI Score

0.001EPSS

2022-11-17 11:15 PM
33
8
cve
cve

CVE-2023-35091

Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <= 2.10.0 versions.

8.8CVSS

8.8AI Score

0.001EPSS

2023-07-11 01:15 PM
15