plugin

Advanced Product Labels For Woocommerce Vulnerabilities

5 known security issues reported for the Advanced Product Labels For Woocommerce WordPress plugin. Most recent disclosed Dec 13, 2022.

2 medium

Running Advanced Product Labels For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

BeRocket Plugins <= (Various Versions) - Missing Authorization

medium

Several BeRocket Plugins for WordPress are vulnerable to authorization bypass due to missing capability checks on functions corresponding to AJAX actions that are available to subscribers. This includes the close_notice, subscribe, disable_rate_notice, feature_request_send, get_plugin_error_ajax, close_notice, and test...

CVSS:
5.4
Affected:
up to 1.2.4
Fixed in:
1.2.4.1
Disclosed:
Dec 13, 2022

CVE-2022-45813 on NVD →

Advanced Product Labels for WooCommerce [advanced-product-labels-for-woocommerce] < 1.2.4.1

unknown

Several BeRocket Plugins for WordPress are vulnerable to authorization bypass due to missing capability checks on functions corresponding to AJAX actions that are available to subscribers. This includes the close_notice, subscribe, disable_rate_notice, feature_request_send, get_plugin_error_ajax, close_notice, and test...

Affected:
up to 1.2.4.1
Fixed in:
1.2.4.1
Disclosed:
Dec 13, 2022

Advanced Product Labels for WooCommerce [advanced-product-labels-for-woocommerce] < 1.2.3.7

unknown

[en] The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting

Affected:
up to 1.2.3.7
Fixed in:
1.2.3.7
Disclosed:
Mar 14, 2022

CVE-2022-0399 on NVD →

Advanced Product Labels for WooCommerce <= 1.2.3.6 - Reflected Cross-Site Scripting

medium

The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 1.2.3.7
Fixed in:
1.2.3.7
Disclosed:
Feb 15, 2022

CVE-2022-0399 on NVD →

Advanced Product Labels for WooCommerce [advanced-product-labels-for-woocommerce] < 1.2.4.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.2.4.1
Fixed in:
1.2.4.1

CVE-2022-45813 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database