SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter
medium
The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 4.4
- Affected:
- up to 4.4.14
- Fixed in:
- 4.5.0
- Disclosed:
- Jul 15, 2026
CVE-2026-15324 on NVD →
SysBasics Customize My Account for WooCommerce – Live My Account Customizer <= 4.3.9 - Reflected Cross-Site Scripting
medium
The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 6.1
- Affected:
- up to 4.3.9
- Fixed in:
- 4.3.10
- Disclosed:
- Jul 1, 2026
CVE-2026-57358 on NVD →
SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
medium
The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_height, min_width, max_height,...
- CVSS:
- 6.4
- Affected:
- up to 4.3.6
- Fixed in:
- 4.3.7
- Disclosed:
- Jun 17, 2026
CVE-2026-12136 on NVD →
SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Site Scripting via 'tab' Parameter
medium
The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 6.1
- Affected:
- up to 4.3.6
- Fixed in:
- 4.3.7
- Disclosed:
- Jun 17, 2026
CVE-2026-12137 on NVD →
SysBasics Customize My Account for WooCommerce [customize-my-account-for-woocommerce] < 2.9.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SysBasics Customize My Account for WooCommerce allows Reflected XSS. This issue affects Customize My Account for WooCommerce: from n/a through 2.8.22.
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
- Disclosed:
- Feb 14, 2025
CVE-2025-24592 on NVD →
SysBasics Customize My Account for WooCommerce <= 2.8.22 - Reflected Cross-Site Scripting
medium
The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.8.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- CVSS:
- 6.1
- Affected:
- up to 2.8.22
- Fixed in:
- 2.9.0
- Disclosed:
- Dec 21, 2024
CVE-2025-24592 on NVD →
SysBasics Customize My Account for WooCommerce <= 2.7.29 - Reflected Cross-Site Scripting via tab Parameter
medium
The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 2.7.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 6.1
- Affected:
- up to 2.7.29
- Fixed in:
- 2.7.30
- Disclosed:
- Nov 9, 2024
CVE-2024-10837 on NVD →
SysBasics Customize My Account for WooCommerce [customize-my-account-for-woocommerce] < 2.7.30
unknown
[en] The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 2.7.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb...
- Affected:
- up to 2.7.30
- Fixed in:
- 2.7.30
- Disclosed:
- Nov 9, 2024
CVE-2024-10837 on NVD →
SysBasics Customize My Account for WooCommerce [customize-my-account-for-woocommerce] < 1.8.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Customize My Account for WooCommerce: from n/a through 1.8.3.
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Mar 15, 2024
CVE-2023-51369 on NVD →
Customize My Account for WooCommerce <= 1.8.3 - Cross-Site Request Forgery via restore_my_account_tabs
medium
The Customize My Account for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.3. This is due to missing or incorrect nonce validation on the restore_my_account_tabs function. This makes it possible for unauthenticated attackers to restore account tabs vi...
- CVSS:
- 4.3
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.4
- Disclosed:
- Dec 26, 2023
CVE-2023-51369 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database