BeRocket Plugins <= (Various Versions) - Missing Authorization
medium
Several BeRocket Plugins for WordPress are vulnerable to authorization bypass due to missing capability checks on functions corresponding to AJAX actions that are available to subscribers. This includes the close_notice, subscribe, disable_rate_notice, feature_request_send, get_plugin_error_ajax, close_notice, and test...
- CVSS:
- 5.4
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4.1
- Disclosed:
- Dec 13, 2022
CVE-2022-45813 on NVD →
Advanced Product Labels for WooCommerce [advanced-product-labels-for-woocommerce] < 1.2.4.1
unknown
Several BeRocket Plugins for WordPress are vulnerable to authorization bypass due to missing capability checks on functions corresponding to AJAX actions that are available to subscribers. This includes the close_notice, subscribe, disable_rate_notice, feature_request_send, get_plugin_error_ajax, close_notice, and test...
- Affected:
- up to 1.2.4.1
- Fixed in:
- 1.2.4.1
- Disclosed:
- Dec 13, 2022
Advanced Product Labels for WooCommerce [advanced-product-labels-for-woocommerce] < 1.2.3.7
unknown
[en] The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 1.2.3.7
- Fixed in:
- 1.2.3.7
- Disclosed:
- Mar 14, 2022
CVE-2022-0399 on NVD →
Advanced Product Labels for WooCommerce <= 1.2.3.6 - Reflected Cross-Site Scripting
medium
The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 1.2.3.7
- Fixed in:
- 1.2.3.7
- Disclosed:
- Feb 15, 2022
CVE-2022-0399 on NVD →
Advanced Product Labels for WooCommerce [advanced-product-labels-for-woocommerce] < 1.2.4.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.2.4.1
- Fixed in:
- 1.2.4.1
CVE-2022-45813 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database