plugin

Personalize Woocommerce Cart Page Vulnerabilities

4 known security issues reported for the Personalize Woocommerce Cart Page WordPress plugin. Most recent disclosed Jan 25, 2025.

1 high 1 medium

Running Personalize Woocommerce Cart Page on your site? Check whether your installed version is affected.

Scan your site free

GoHero Store Customizer for WooCommerce [personalize-woocommerce-cart-page] < 4.0

unknown

[en] The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wooh_action_settings_save_frontend() function in all versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to update limite...

Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Jan 25, 2025

CVE-2024-12826 on NVD →

GoHero Store Customizer for WooCommerce <= 3.5 - Missing Authorization to Unuthenticated Settings Update

medium

The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wooh_action_settings_save_frontend() function in all versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to update limited plu...

CVSS:
4.3
Affected:
up to 3.5
Fixed in:
4.0
Disclosed:
Jan 24, 2025

CVE-2024-12826 on NVD →

GoHero Store Customizer for WooCommerce [personalize-woocommerce-cart-page] < 2.5

unknown

[en] Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

Affected:
up to 2.5
Fixed in:
2.5
Disclosed:
Jul 5, 2019

CVE-2019-5979 on NVD →

Personalized WooCommerce Cart Page <= 2.4 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVSS:
8.8
Affected:
up to 2.4
Fixed in:
2.5
Disclosed:
Jun 19, 2019

CVE-2019-5979 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database