Happy WooCommerce FAQs & AI FAQ Generator [faq-for-woocommerce] < 1.6.4
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Optemiz XPlainer - WooCommerce Product FAQ allows Reflected XSS.This issue affects XPlainer - WooCommerce Product FAQ: from n/a through 1.6.3.
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Jul 21, 2024
CVE-2024-37515 on NVD →
Happy WooCommerce FAQs & AI FAQ Generator [faq-for-woocommerce] < 1.7.1
unknown
[en] The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-le...
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Jul 9, 2024
CVE-2024-5704 on NVD →
Happy WooCommerce FAQs & AI FAQ Generator [faq-for-woocommerce] < 1.7.1
unknown
[en] The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ffw_activate_template' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers...
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Jul 9, 2024
CVE-2024-5669 on NVD →
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ffw_activate_template' function in all versions up to, and including, 1.7.0. This makes it possible for authenticated attackers, wit...
- CVSS:
- 6.4
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.1
- Disclosed:
- Jul 8, 2024
CVE-2024-5669 on NVD →
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update
medium
The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. ffw_insert_new_faq, ffw_hide_discount_notice, ffw_delete_all_faqs, ffw_delete_single_faq, etc...) in all versions...
- CVSS:
- 4.3
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.1
- Disclosed:
- Jul 8, 2024
CVE-2024-5704 on NVD →
XPlainer - WooCommerce Product FAQ <= 1.6.3 - Reflected Cross-Site Scripting
medium
The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...
- CVSS:
- 6.1
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Jul 5, 2024
CVE-2024-37515 on NVD →
Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout
medium
The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to opt-in or opt-out of tracking. This was patched in...
- CVSS:
- 4.3
- Affected:
- up to 1.5.0
- Fixed in:
- 1.5.1
- Disclosed:
- Apr 11, 2024
CVE-2024-32110 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 1.3.35
- Fixed in:
- 1.4.0
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Happy WooCommerce FAQs & AI FAQ Generator [faq-for-woocommerce] < 1.4.0
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.0
CVE-2023-33999 on NVD →
Happy WooCommerce FAQs & AI FAQ Generator [faq-for-woocommerce] < 1.5.1
unknown
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1
CVE-2024-32110 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database