plugin

Booster Elite For Woocommerce Vulnerabilities

16 known security issues reported for the Booster Elite For Woocommerce WordPress plugin. Most recent disclosed Jun 4, 2024.

2 high 6 medium

Running Booster Elite For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

WordPress Booster Elite for WooCommerce [booster-elite-for-woocommerce] < 7.1.3

unknown

[en] Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.3.

Affected:
up to 7.1.3
Fixed in:
7.1.3
Disclosed:
Jun 4, 2024

CVE-2023-51511 on NVD →

WordPress Booster Elite for WooCommerce [booster-elite-for-woocommerce] < 7.1.2

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Elite for WooCommerce.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.2.

Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Mar 28, 2024

CVE-2023-52234 on NVD →

Elite Booster for WooCommerce <= 7.1.7 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wc_add_new_product() function in all versions up to, and including, 7.1.7. This makes it possible for customer-level attackers, and above, to upload arbitrary files on the affected s...

CVSS:
8.8
Affected:
up to 7.1.7
Fixed in:
7.1.8
Disclosed:
Mar 7, 2024

CVE-2024-1986 on NVD →

WordPress Booster Elite for WooCommerce [booster-elite-for-woocommerce] < 7.1.8

unknown

[en] The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wc_add_new_product() function in all versions up to, and including, 7.1.7. This makes it possible for customer-level attackers, and above, to upload arbitrary files on the affec...

Affected:
up to 7.1.8
Fixed in:
7.1.8
Disclosed:
Mar 7, 2024

CVE-2024-1986 on NVD →

Booster Elite for WooCommerce < 7.1.2 - Missing Authorization to Order Information Disclosure

medium

The Booster Elite for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 7.1.2 (exclusive). This makes it possible for authenticated attackers, with subscriber-level access and above, to view arbitrary order information.

CVSS:
4.3
Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Jan 5, 2024

CVE-2023-52234 on NVD →

Booster Elite for WooCommerce <= 7.1.2 - Authenticated(Subscriber+) Content Injection

medium

The Booster Elite for WooCommerce plugin for WordPress is vulnerable to content injection via an unknown parameter in all versions up to and including 7.1.2 due to insufficient capability checks. This makes it possible for authenticated attackers, with subscriber access and above, to create and edit content using the p...

CVSS:
4.3
Affected:
up to 7.1.3
Fixed in:
7.1.3
Disclosed:
Dec 27, 2023

CVE-2023-51511 on NVD →

WordPress Booster Elite for WooCommerce [booster-elite-for-woocommerce] < 6.0.1

unknown

[en] The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, Booster Elite for WooCommerce WordPress plugin before 6.0.1 have either flawed CSRF checks or are missing them completely in numerous places, allowing attackers to make logged in users perform unw...

Affected:
up to 6.0.1
Fixed in:
6.0.1
Disclosed:
Jan 23, 2023

CVE-2022-4017 on NVD →

Booster (<= 6.0.0), Booster Plus (<= 6.0.0), and Booster Elite (<= 6.0.0) for WooCommerce - Cross-Site Request Forgery

medium

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.0 (Booster), 6.0.0 (Plus), and 6.0.0 (Elite). This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthentica...

CVSS:
5.4
Affected:
up to 6.0.0
Fixed in:
6.0.1
Disclosed:
Jan 2, 2023

CVE-2022-4017 on NVD →

WordPress Booster Elite for WooCommerce [booster-elite-for-woocommerce] < 6.0.0

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, Booster Elite for WooCommerce WordPress plugin before 6.0.0 do not escape some URLs and parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 6.0.0
Fixed in:
6.0.0
Disclosed:
Dec 26, 2022

CVE-2022-4227 on NVD →

WordPress Booster Elite for WooCommerce [booster-elite-for-woocommerce] < 1.1.8

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete a...

Affected:
up to 1.1.8
Fixed in:
1.1.8
Disclosed:
Dec 12, 2022

CVE-2022-4016 on NVD →

Booster (<= 5.6.2), Booster Plus (< 6.0.0), and Booster Elite (< 6.0.0) for WooCommerce - Reflected Cross-Site Scripting

medium

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.2 (Booster), as well as versions below 6.0.0 (Plus and Elite). This is due to insufficient input sanitization and output escaping. This makes it possible fo...

CVSS:
6.1
Affected:
up to 6.0.0
Fixed in:
6.0.0
Disclosed:
Dec 5, 2022

CVE-2022-4227 on NVD →

Booster (<= 5.6.6), Booster Plus (<= 5.6.5), and Booster Elite (<= 1.1.7) for WooCommerce - Cross-Site Request Forgery leading to Arbitrary Custom Role Creation/Deletion

medium

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Booster), 5.6.5 (Plus), and 1.1.7 (Elite). This is due to missing or incorrect nonce validation on functions such as 'process_actions' and 'get_delete_all_cu...

CVSS:
5.4
Affected:
up to 1.1.7
Fixed in:
1.1.8
Disclosed:
Nov 21, 2022

CVE-2022-4016 on NVD →

WordPress Booster Elite for WooCommerce [booster-elite-for-woocommerce] < 1.1.7

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not have CSRF check in place when deleting files uploaded at the checkout, allowing attackers to make a logged in shop manager or adm...

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Nov 21, 2022

CVE-2022-3763 on NVD →

WordPress Booster Elite for WooCommerce [booster-elite-for-woocommerce] < 1.1.7

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not validate files to download in some of its modules, which could allow ShopManager and Admin to download arbitrary files from the s...

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Nov 21, 2022

CVE-2022-3762 on NVD →

Booster Elite for WooCommerce < 1.1.7 - Cross-Site Request Forgery

high

The Booster Elite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 1.1.7. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to delete files uploaded during a check-out, g...

CVSS:
8.8
Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Oct 31, 2022

CVE-2022-3763 on NVD →

Booster Elite for WooCommerce < 1.1.7 - Authenticated (Admin/Shop Manager+) Arbitrary File Download

medium

The Booster Elite for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, but not including, 1.1.7. This makes it possible for administrator-level attackers to download files from the website, leading to the extraction of sensitive user or configuration data.

CVSS:
4.9
Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Oct 31, 2022

CVE-2022-3762 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database