Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 7.2.5
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster Plus for WooCommerce allows Reflected XSS.This issue affects Booster Plus for WooCommerce: from n/a through 7.2.4.
- Affected:
- up to 7.2.5
- Fixed in:
- 7.2.5
- Disclosed:
- May 19, 2025
CVE-2025-39446 on NVD →
Booster Plus for WooCommerce <= 7.2.4 - Reflected Cross-Site Scripting
medium
The Booster Plus for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 7.2.4
- Fixed in:
- 7.2.5
- Disclosed:
- Apr 17, 2025
CVE-2025-39446 on NVD →
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 7.1.3
unknown
[en] Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.3.
- Affected:
- up to 7.1.3
- Fixed in:
- 7.1.3
- Disclosed:
- Jun 9, 2024
CVE-2023-52230 on NVD →
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 7.1.2
unknown
[en] Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.2
- Disclosed:
- Jun 9, 2024
CVE-2023-52232 on NVD →
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 7.1.2
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.2
- Disclosed:
- Mar 28, 2024
CVE-2023-52231 on NVD →
Booster Plus for WooCommerce < 7.1.2 - Missing Authorization to Order Information Disclosure
medium
The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on an unknown function in all versions up to 7.1.2 (exclusive). This makes it possible for authenticated attackers, with susbcriber-level access and above, to access arbitrary order infor...
- CVSS:
- 4.3
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.2
- Disclosed:
- Jan 5, 2024
CVE-2023-52231 on NVD →
Booster Plus for WooCommerce < 7.1.3 - Missing Authorization to Arbitrary Options Disclosure
medium
The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on an unknown function in all versions up to 7.1.3 (exclusive). This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve arbitrary WordPress...
- CVSS:
- 4.3
- Affected:
- up to 7.1.3
- Fixed in:
- 7.1.3
- Disclosed:
- Jan 5, 2024
CVE-2023-52230 on NVD →
Booster Plus for WooCommerce < 7.1.2 - Missing Authorization to Arbitrary Page/Post Deletion
medium
The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on an unknown function in all versions up to 7.1.2 (exclusive). This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary pages and pos...
- CVSS:
- 4.3
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.2
- Disclosed:
- Jan 5, 2024
CVE-2023-52232 on NVD →
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.1
unknown
[en] The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, Booster Elite for WooCommerce WordPress plugin before 6.0.1 have either flawed CSRF checks or are missing them completely in numerous places, allowing attackers to make logged in users perform unw...
- Affected:
- up to 6.0.1
- Fixed in:
- 6.0.1
- Disclosed:
- Jan 23, 2023
CVE-2022-4017 on NVD →
Booster (<= 6.0.0), Booster Plus (<= 6.0.0), and Booster Elite (<= 6.0.0) for WooCommerce - Cross-Site Request Forgery
medium
The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.0 (Booster), 6.0.0 (Plus), and 6.0.0 (Elite). This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthentica...
- CVSS:
- 5.4
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.1
- Disclosed:
- Jan 2, 2023
CVE-2022-4017 on NVD →
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.0
unknown
[en] The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, Booster Elite for WooCommerce WordPress plugin before 6.0.0 do not escape some URLs and parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Dec 26, 2022
CVE-2022-4227 on NVD →
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.6
unknown
[en] The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete a...
- Affected:
- up to 5.6.6
- Fixed in:
- 5.6.6
- Disclosed:
- Dec 12, 2022
CVE-2022-4016 on NVD →
Booster (<= 5.6.2), Booster Plus (< 6.0.0), and Booster Elite (< 6.0.0) for WooCommerce - Reflected Cross-Site Scripting
medium
The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.2 (Booster), as well as versions below 6.0.0 (Plus and Elite). This is due to insufficient input sanitization and output escaping. This makes it possible fo...
- CVSS:
- 6.1
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Dec 5, 2022
CVE-2022-4227 on NVD →
Booster (<= 5.6.6), Booster Plus (<= 5.6.5), and Booster Elite (<= 1.1.7) for WooCommerce - Cross-Site Request Forgery leading to Arbitrary Custom Role Creation/Deletion
medium
The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Booster), 5.6.5 (Plus), and 1.1.7 (Elite). This is due to missing or incorrect nonce validation on functions such as 'process_actions' and 'get_delete_all_cu...
- CVSS:
- 5.4
- Affected:
- up to 5.6.5
- Fixed in:
- 5.6.6
- Disclosed:
- Nov 21, 2022
CVE-2022-4016 on NVD →
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5
unknown
[en] The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not validate files to download in some of its modules, which could allow ShopManager and Admin to download arbitrary files from the s...
- Affected:
- up to 5.6.5
- Fixed in:
- 5.6.5
- Disclosed:
- Nov 21, 2022
CVE-2022-3762 on NVD →
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5
unknown
[en] The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not have CSRF check in place when deleting files uploaded at the checkout, allowing attackers to make a logged in shop manager or adm...
- Affected:
- up to 5.6.5
- Fixed in:
- 5.6.5
- Disclosed:
- Nov 21, 2022
CVE-2022-3763 on NVD →
Booster for WooCommerce (Free <= 5.6.6, Premium <= 5.6.4) - Cross-Site Request Forgery to File Deletion
high
The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Free) and 5.6.4 (Premium). This is due to missing or incorrect nonce validation when deleting files uploaded during checkout. This makes it possible for unauthenticated attackers to dele...
- CVSS:
- 8.8
- Affected:
- up to 5.6.4
- Fixed in:
- 5.6.5
- Disclosed:
- Oct 31, 2022
CVE-2022-3763 on NVD →
Booster (<= 5.6.6) and Booster Plus (<= 5.6.4) for WooCommerce - Authenticated (Shop Manager+) Information Exposure via Arbitrary File Download
medium
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file downloads due to missing sanitization and filename validation of a user-supplied parameter in versions up to, and including, 5.6.6 (5.6.4 for Booster Plus). This makes it possible for authenticated attackers, with Shop Manager-level permis...
- CVSS:
- 6.5
- Affected:
- up to 5.6.4
- Fixed in:
- 5.6.5
- Disclosed:
- Oct 27, 2022
CVE-2022-3762 on NVD →
Booster for WooCommerce (Free <= 5.6.2 and Premium <= 5.6.0) - Authenticated (Subscriber+) Order Modification
medium
The Booster for WooCommerce plugin for WordPress is vulnerable to order modification due to a missing capability/authorization check in versions up to, and including, 5.6.2 (free) or 5.6.0 (premium). This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify their own ord...
- CVSS:
- 6.5
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.1
- Disclosed:
- Sep 19, 2022
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.1
unknown
Authenticated Order Status Update vulnerability discovered by WPScan in WordPress Booster Plus for WooCommerce premium plugin (versions <= 5.6.0).
Update the WordPress Booster Plus for WooCommerce plugin to the latest available version (at least 5.6.1).
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.1
- Disclosed:
- Sep 19, 2022
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.1
unknown
The plugins allow users to update their own order status via a settings defined by admins when the My Account module is enabled, however does not ensure that the status set is allowed. As a result, users could set arbitrary status to their own orders, making them paid without actually paying for them even though admins...
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database