Lucene search

K

WC Vendors Security Vulnerabilities

cve
cve

CVE-2023-48327

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Vendors WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors.This issue affects WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors: from.....

7.6CVSS

7.3AI Score

0.001EPSS

2023-12-19 09:15 PM
48
cve
cve

CVE-2022-2657

The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order...

4.3CVSS

4.8AI Score

0.001EPSS

2022-09-05 01:15 PM
35
7