Vulnerabilities (CVE)

Filtered by vendor Visser Subscribe
Total 8 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-46822 1 Visser 1 Store Exporter For Woocommerce 2023-12-10 N/A 6.1 MEDIUM
Unauth. Reflected Cross-Site Scripting') vulnerability in Visser Labs Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin <= 2.7.2 versions.
CVE-2022-1546 1 Visser 1 Woocommerce - Product Importer 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-0149 1 Visser 1 Store Exporter For Woocommerce 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.
CVE-2021-25077 1 Visser 1 Store Toolkit For Woocommerce 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting
CVE-2016-10922 1 Visser 1 Store Toolkit For Woocommerce 2023-12-10 7.5 HIGH 9.8 CRITICAL
The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
CVE-2016-10923 1 Visser 1 Store Toolkit For Woocommerce 2023-12-10 7.5 HIGH 9.8 CRITICAL
The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.
CVE-2016-10935 1 Visser 1 Store Exporter For Woocommerce 2023-12-10 7.5 HIGH 9.8 CRITICAL
The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.
CVE-2019-11807 1 Visser 1 Woocommerce Checkout Manager 2023-12-10 6.4 MEDIUM 7.5 HIGH
The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.