License Manager for WooCommerce <= 3.0.18 - Authenticated (Customer+) SQL Injection
medium
The License Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.0.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.5
- Affected:
- up to 3.0.18
- Fixed in:
- 3.0.19
- Disclosed:
- Aug 18, 2026
CVE-2026-73345 on NVD →
License Manager for WooCommerce <= 3.0.17 - Authenticated (Customer+) Arbitrary Content Deletion
medium
The License Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in all versions up to, and including, 3.0.17. This makes it possible for authenticated attackers, with Custom-level access and above, to delete arbitrary content.
- CVSS:
- 4.3
- Affected:
- up to 3.0.17
- Fixed in:
- 3.0.18
- Disclosed:
- Jul 21, 2026
CVE-2026-61958 on NVD →
License Manager for WooCommerce <= 3.0.15 - Unauthenticated Insecure Direct Object Reference
medium
The License Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.15 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform unauthorized actions.
- CVSS:
- 5.3
- Affected:
- up to 3.0.15
- Fixed in:
- 3.0.16
- Disclosed:
- Jun 19, 2026
CVE-2026-56013 on NVD →
License Manager for WooCommerce <= 3.0.12 - Authenticated (Administrator+) SQL Injection
medium
The License Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrat...
- CVSS:
- 4.9
- Affected:
- up to 3.0.12
- Fixed in:
- 3.0.13
- Disclosed:
- Sep 5, 2025
CVE-2025-58788 on NVD →
License Manager for WooCommerce [license-manager-for-woocommerce] <= 3.0.12 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce allows Blind SQL Injection. This issue affects License Manager for WooCommerce: from n/a through 3.0.12.
- Affected:
- up to 3.0.12
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2025
CVE-2025-58788 on NVD →
License Manager for WooCommerce [license-manager-for-woocommerce] < 3.0.10 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPExperts.io License Manager for WooCommerce allows Reflected XSS. This issue affects License Manager for WooCommerce: from n/a through 3.0.9.
- Affected:
- up to 3.0.10
- Fixed in:
- 3.0.10
- Disclosed:
- Apr 17, 2025
CVE-2025-32522 on NVD →
License Manager for WooCommerce <= 3.0.9 - Reflected Cross-Site Scripting
medium
The License Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.10
- Disclosed:
- Apr 10, 2025
CVE-2025-32522 on NVD →
License Manager for WooCommerce [license-manager-for-woocommerce] < 2.2.6 (closed)
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
License Manager for WooCommerce [license-manager-for-woocommerce] < 3.0.7 (closed)
unknown
[en] The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with admin dashboard ac...
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Jun 21, 2024
CVE-2024-1639 on NVD →
License Manager for WooCommerce <= 3.0.6 - Improper Authorization to Authenticated(Contributor+) Sensitive Information Exposure
medium
The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.6. This makes it possible for authenticated attackers, with admin dashboard access...
- CVSS:
- 6.5
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Jun 20, 2024
CVE-2024-1639 on NVD →
License Manager for WooCommerce [license-manager-for-woocommerce] < 2.2.11 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LicenseManager License Manager for WooCommerce license-manager-for-woocommerce allows SQL Injection.This issue affects License Manager for WooCommerce: from n/a through 2.2.10.
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.11
- Disclosed:
- Nov 30, 2023
CVE-2023-48742 on NVD →
License Manager for WooCommerce <= 2.2.10 - Authenticated (Administrator+) SQL Injection
high
The License Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the orderby parameter in versions up to, and including, 2.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated a...
- CVSS:
- 7.2
- Affected:
- up to 2.2.10
- Fixed in:
- 2.2.11
- Disclosed:
- Nov 23, 2023
CVE-2023-48742 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 2.2.5 – 2.2.9
- Fixed in:
- 2.3-beta.1
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
License Manager for WooCommerce [license-manager-for-woocommerce] < 2.2.6 (closed)
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- Mar 4, 2022
License Manager for WooCommerce [license-manager-for-woocommerce] < 2.2.6 (closed)
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress License Manager for WooCommerce plugin (versions <= 2.2.5).
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- Feb 28, 2022
License Manager for WooCommerce [license-manager-for-woocommerce] < 2.2.6 (closed)
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress License Manager for WooCommerce plugin (versions <= 2.2.5).
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- Feb 28, 2022
License Manager for WooCommerce [license-manager-for-woocommerce] < 2.2.10 (closed)
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.2.10
- Fixed in:
- 2.2.10
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database