GG Woo Feed for WooCommerce Shopping Feed <= 1.2.6 - Missing Authorization
medium
The GG Woo Feed for WooCommerce Shopping Feed on Google Facebook and Other Channels plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions in the /inc/Core/ajax-functions.php file in all versions up to, and including, 1.2.6. This makes it possible f...
- CVSS:
- 4.3
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Apr 15, 2024
CVE-2024-32519 on NVD →
GTG Product Feed for Shopping <= 1.2.4 - Missing Authorization to Unauthenticated Plugin Settings Update
medium
The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' function in versions up to, and including, 1.2.4. This makes it possible for unauthenticated attackers to update plugin settings.
- CVSS:
- 6.5
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.5
- Disclosed:
- Dec 15, 2023
CVE-2023-6638 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database