FG PrestaShop to WooCommerce <= 4.45.1 - Unauthenticated Sensitive Information Disclosure
medium
The FG PrestaShop to WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.45.1. This makes it possible for unauthenticated attackers to view data in log files.
- CVSS:
- 5.3
- Affected:
- up to 4.45.1
- Fixed in:
- 4.47.0
- Disclosed:
- Mar 29, 2024
CVE-2024-30511 on NVD →
FG Drupal to WordPress <= 3.67.0 - Cross-Site Request Forgery via ajax_importer
medium
The FG Drupal to WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.67.0. This is due to missing or incorrect nonce validation on the ajax_importer() function. This makes it possible for unauthenticated attackers to delete logs via a forged request granted the...
- CVSS:
- 4.3
- Affected:
- up to 4.44.3
- Fixed in:
- 4.45.0
- Disclosed:
- Feb 2, 2024
CVE-2024-24837 on NVD →
FG PrestaShop to WooCommerce Plugin <= 3.19.1 - Cross-Site Scripting
medium
The FG PrestaShop to WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ajax_importer() function in versions up to, and including, 3.19.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 3.19.1
- Fixed in:
- 3.20.0
- Disclosed:
- Aug 24, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database