Checkout Mestres do WP for WooCommerce 8.6.5 - 8.7.5 - Unauthenticated Arbitrary Options Update
critical
The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attackers to update arbitr...
- CVSS:
- 9.8
- Affected:
- 8.6.5 – 8.7.5
- Fix:
- No patched version reported
- Disclosed:
- Mar 28, 2025
CVE-2025-2266 on NVD →
Checkout Mestres WP <= 8.6 - Authenticated (Admin+) Local File Inclusion
high
The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the server, allowing the execution of...
- CVSS:
- 7.2
- Affected:
- up to 8.6
- Fixed in:
- 8.6.1
- Disclosed:
- Sep 24, 2024
CVE-2024-44030 on NVD →
Checkout Mestres WP <= 7.1.9.6 - Authentication Bypass via Password Reset
critical
The Checkout Mestres WP plugin for WordPress is vulnerable to authentication due to a weak password reset functionality in all versions up to, and including, 7.1.9.6. This makes it possible for unauthenticated attackers to reset the password of arbitrary users to a guessable value based on the current time.
- CVSS:
- 9.8
- Affected:
- up to 7.1.9.6
- Fixed in:
- 7.1.9.8
- Disclosed:
- Dec 27, 2023
CVE-2023-51472 on NVD →
Checkout Mestres WP <= 7.1.9.6 - Missing Authorization to Unauthenticated Arbitrary Options Update
critical
The Checkout Mestres WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.1.9.6. This makes it possible for unauthenticated attackers to update arbitrary site options.
- CVSS:
- 9.8
- Affected:
- up to 7.1.9.6
- Fixed in:
- 7.1.9.8
- Disclosed:
- Dec 27, 2023
CVE-2023-51471 on NVD →
Checkout Mestres WP <= 7.1.9.6 - Unauthenticated SQL Injection
critical
The Checkout Mestres WP plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, and including, 7.1.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...
- CVSS:
- 9.8
- Affected:
- up to 7.1.9.6
- Fixed in:
- 7.1.9.8
- Disclosed:
- Dec 27, 2023
CVE-2023-51469 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database