Zorem Local Pickup [advanced-local-pickup-for-woocommerce] < 1.6.3
unknown
[en] Missing Authorization vulnerability in zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.2.
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Jun 9, 2024
CVE-2024-31283 on NVD →
Zorem Local Pickup [advanced-local-pickup-for-woocommerce] < 1.6.2
unknown
[en] Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.1.
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Jun 9, 2024
CVE-2024-32814 on NVD →
Advanced Local Pickup for WooCommerce <= 1.6.1 - Missing Authorization to Notice Dismissal
medium
The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices_for_alp_pro() function in versions up to, and including, 1.6.1. This makes it possible for unauthenticated attackers to dismiss upgrade notices
- CVSS:
- 6.5
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.2
- Disclosed:
- Apr 22, 2024
CVE-2024-32814 on NVD →
Advanced Local Pickup for WooCommerce < 1.6.2 - Missing Authorization to Notice Dismissal
medium
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Apr 22, 2024
CVE-2024-32814 on NVD →
Advanced Local Pickup for WooCommerce <= 1.6.2 - Missing Authorization
medium
The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ~/include/customizer/customizer-admin.php file in versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to update plugin...
- CVSS:
- 6.5
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- Apr 5, 2024
CVE-2024-31283 on NVD →
Advanced Local Pickup for WooCommerce < 1.6.3 - Missing Authorization
medium
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Apr 5, 2024
CVE-2024-31283 on NVD →
Zorem Local Pickup [advanced-local-pickup-for-woocommerce] < 1.5.3
unknown
[en] Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.5.2.
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jan 17, 2024
CVE-2022-40702 on NVD →
Zorem Local Pickup [advanced-local-pickup-for-woocommerce] < 1.6.0
unknown
[en] The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Nov 22, 2023
CVE-2023-2841 on NVD →
Advanced Local Pickup for WooCommerce <= 1.5.5 - Authenticated (Administrator+) SQL Injection
high
The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for auth...
- CVSS:
- 7.2
- Affected:
- up to 1.5.5
- Fixed in:
- 1.6.0
- Disclosed:
- Oct 21, 2023
CVE-2023-2841 on NVD →
Advanced Local Pickup for WooCommerce < 1.6.0 - Authenticated (Administrator+) SQL Injection
high
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Oct 21, 2023
CVE-2023-2841 on NVD →
Advanced Local Pickup for WooCommerce <= 1.5.2 - Cross-Site Request Forgery
medium
The Advanced Local Pickup for WooCommerce for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the functions wclp_update_state_dropdown_fun, wclp_update_work_hours_list_fun, wclp_update_edit_location_form_fun, and wclp...
- CVSS:
- 4.3
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- Mar 31, 2023
Zorem Local Pickup [advanced-local-pickup-for-woocommerce] < 1.5.3
unknown
The Advanced Local Pickup for WooCommerce for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the functions wclp_update_state_dropdown_fun, wclp_update_work_hours_list_fun, wclp_update_edit_location_form_fun, and wclp...
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Mar 31, 2023
Advanced Local Pickup for WooCommerce <= 1.5.2 - Missing Authorization
medium
The Advanced Local Pickup for WooCommerce for WordPress is vulnerable to unauthorized access of AJAX actions due to a missing capability check on the functions wclp_update_state_dropdown_fun, wclp_update_work_hours_list_fun, wclp_update_edit_location_form_fun, and wclp_apply_work_hours_fun in versions up to, and includ...
- CVSS:
- 4.3
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- Mar 28, 2023
CVE-2022-40702 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database