plugin

Post New Vulnerabilities

1 known security issue reported for the Post New WordPress plugin. Most recent disclosed Mar 25, 2024.

1 medium

Running Post New on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce <= 8.5.2 - Missing Authorization to Private/Draft Product Disclosure

medium

The WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to insufficient restrictions in the product shortcode in all versions up to, and including, 8.5.2. This makes it possible for authenticated attackers, with contributor-level access and above, to view private and draft products.

CVSS:
4.3
Affected:
up to 8.6
Fixed in:
8.6
Disclosed:
Mar 25, 2024

CVE-2024-1310 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database