plugin

Ean For Woocommerce Vulnerabilities

12 known security issues reported for the Ean For Woocommerce WordPress plugin. Most recent disclosed May 19, 2025.

1 high 5 medium

Running Ean For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

EAN for WooCommerce <= 5.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pa...

CVSS:
6.4
Affected:
up to 5.4.6
Fixed in:
5.4.7
Disclosed:
May 19, 2025

CVE-2025-48249 on NVD →

EAN Barcode Generator for WooCommerce: UPC, ISBN &amp; GTIN Inventory [ean-for-woocommerce] < 5.4.7

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for WooCommerce allows Stored XSS. This issue affects EAN for WooCommerce: from n/a through 5.4.6.

Affected:
up to 5.4.7
Fixed in:
5.4.7
Disclosed:
May 19, 2025

CVE-2025-48249 on NVD →

EAN Barcode Generator for WooCommerce: UPC, ISBN &amp; GTIN Inventory [ean-for-woocommerce] < 5.4.0

unknown

[en] Missing Authorization vulnerability in WPFactory EAN for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through 5.3.5.

Affected:
up to 5.4.0
Fixed in:
5.4.0
Disclosed:
Mar 27, 2025

CVE-2025-22673 on NVD →

EAN for WooCommerce <= 5.3.5 - Missing Authorization

medium

The EAN Barcode Generator for WooCommerce: UPC, ISBN & GTIN Inventory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.3.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to per...

CVSS:
4.3
Affected:
up to 5.3.5
Fixed in:
5.4.0
Disclosed:
Feb 3, 2025

CVE-2025-22673 on NVD →

EAN Barcode Generator for WooCommerce: UPC, ISBN &amp; GTIN Inventory [ean-for-woocommerce] < 4.9.0

unknown

[en] Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.

Affected:
up to 4.9.0
Fixed in:
4.9.0
Disclosed:
May 17, 2024

CVE-2024-34370 on NVD →

EAN for WooCommerce <= 4.8.9 - Authenticated (Shop Manager+) Arbitrary Options Update

high

The EAN for WooCommerce plugin for WordPress is vulnerable to arbitrary options updates n all versions up to, and including, 4.8.9. This is due to insufficient restrictions on option values that can be supplied. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbi...

CVSS:
7.2
Affected:
up to 4.8.9
Fixed in:
4.9.0
Disclosed:
May 3, 2024

CVE-2024-34370 on NVD →

EAN Barcode Generator for WooCommerce: UPC, ISBN &amp; GTIN Inventory [ean-for-woocommerce] < 4.9.3

unknown

[en] The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level a...

Affected:
up to 4.9.3
Fixed in:
4.9.3
Disclosed:
Apr 18, 2024

CVE-2023-6897 on NVD →

EAN Barcode Generator for WooCommerce: UPC, ISBN &amp; GTIN Inventory [ean-for-woocommerce] < 4.9.3

unknown

[en] The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

Affected:
up to 4.9.3
Fixed in:
4.9.3
Disclosed:
Apr 18, 2024

CVE-2023-6892 on NVD →

EAN for WooCommerce <= 4.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via alg_wc_ean_product_meta Shortcode

medium

The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 4.9.2
Fixed in:
4.9.3
Disclosed:
Apr 17, 2024

CVE-2023-6892 on NVD →

EAN for WooCommerce <= 4.9.2 - Insecure Direct Object Reference to Sensitve Information Exposure via Shortcode

medium

The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
4.3
Affected:
up to 4.9.2
Fixed in:
4.9.3
Disclosed:
Apr 17, 2024

CVE-2023-6897 on NVD →

EAN Barcode Generator for WooCommerce: UPC, ISBN &amp; GTIN Inventory [ean-for-woocommerce] < 4.4.3

unknown

[en] The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Feb 6, 2023

CVE-2023-0062 on NVD →

EAN for WooCommerce <= 4.4.2 - Authenticated (Contributor+ )Stored Cross-Site Scripting via Shortcode

medium

The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level...

CVSS:
6.4
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Jan 11, 2023

CVE-2023-0062 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database