WebToffee Plugins <= (Various Versions) - Arbitrary User Creation
high
The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
- CVSS:
- 8.8
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Mar 11, 2020
CVE-2020-12074 on NVD →
Order XML File Export Import for WooCommerce [order-xml-file-export-import-for-woocommerce] < 1.3.9 (closed)
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered by WordFence in WordPress Order XML File Export Import for WooCommerce plugin (versions <= 1.3.0).
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.9
- Disclosed:
- Mar 11, 2020
Order XML File Export Import for WooCommerce [order-xml-file-export-import-for-woocommerce] < 1.2.3 (closed)
unknown
Cross-Site Scripting (XSS) vulnerability found in WordPress Order XML File Export Import for WooCommerce plugin (versions <= 1.2.2).
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Aug 1, 2019
Order XML File Export Import for WooCommerce < 1.2.3 - Cross-Site Scripting
medium
The Order XML File Export Import for WooCommerce Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- CVSS:
- 6.1
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Dec 28, 2018
Order XML File Export Import for WooCommerce [order-xml-file-export-import-for-woocommerce] < 1.2.3 (closed)
unknown
The Order XML File Export Import for WooCommerce Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Dec 28, 2018
Order XML File Export Import for WooCommerce [order-xml-file-export-import-for-woocommerce] < 1.2.3 (closed)
unknown
The Order XML File Export Import for WooCommerce WordPress plugin was affected by a XSS security vulnerability.
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database