Lucene search

K

Orders Tracking For Woocommerce Security Vulnerabilities

cve
cve

CVE-2021-25062

The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

6.1CVSS

6AI Score

0.001EPSS

2022-01-24 08:15 AM
28
cve
cve

CVE-2023-4216

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however lim...

2.7CVSS

4AI Score

0.001EPSS

2023-09-04 12:15 PM
34
cve
cve

CVE-2024-4039

The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. ...

6.5CVSS

7.4AI Score

0.001EPSS

2024-05-14 03:42 PM
8