Lucene search

K

WPClever Security Vulnerabilities

cve
cve

CVE-2022-0397

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting

5.4CVSS

5.3AI Score

0.001EPSS

2022-03-28 06:15 PM
61
cve
cve

CVE-2022-1465

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.

6.1CVSS

6AI Score

0.001EPSS

2022-05-16 03:15 PM
52
3
cve
cve

CVE-2023-34386

Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.

8.8CVSS

8.8AI Score

0.001EPSS

2023-11-09 06:15 PM
12
cve
cve

CVE-2023-52127

Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Product Bundles for WooCommerce.This issue affects WPC Product Bundles for WooCommerce: from n/a through 7.3.1.

8.8CVSS

8.7AI Score

0.001EPSS

2024-01-05 09:15 AM
19
cve
cve

CVE-2024-2838

The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wooco_components[0][name]' parameter in all versions up to, and including, 7.2.7 due to insufficient input sanitization and output escaping and missing authorization on the ajax_sav...

6.4CVSS

5.7AI Score

0.0004EPSS

2024-04-27 04:15 AM
31
cve
cve

CVE-2024-30537

Missing Authorization vulnerability in WPClever WPC Badge Management for WooCommerce.This issue affects WPC Badge Management for WooCommerce: from n/a through 2.4.0.

8.8CVSS

4.8AI Score

0.001EPSS

2024-06-09 09:15 AM
33
cve
cve

CVE-2024-32520

Missing Authorization vulnerability in WPClever WPC Grouped Product for WooCommerce.This issue affects WPC Grouped Product for WooCommerce: from n/a through 4.4.2.

4.3CVSS

6.8AI Score

0.0004EPSS

2024-04-17 08:15 AM
35
cve
cve

CVE-2024-32687

Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.0.3.

4.3CVSS

6.8AI Score

0.0004EPSS

2024-04-22 11:15 AM
40