WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'filterMobileText' Block Attribute
medium
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...
- CVSS:
- 6.4
- Affected:
- up to 4.4.24
- Fixed in:
- 4.5.0
- Disclosed:
- Jul 28, 2026
CVE-2026-17161 on NVD →
WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'currentPostId' Block Attribute
medium
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 4.4.24
- Fixed in:
- 4.5.0
- Disclosed:
- Jul 28, 2026
CVE-2026-17162 on NVD →
WowStore - WordPress WowStore - Store Builder & Product Blocks for WooCommerce plugin <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter vulnerability
critical
WordPress WowStore - Store Builder & Product Blocks for WooCommerce plugin <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter vulnerability
- CVSS:
- 9.3
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.4
- Disclosed:
- Mar 17, 2026
WowStore – Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter
high
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 4.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...
- CVSS:
- 7.5
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.4
- Disclosed:
- Mar 16, 2026
CVE-2026-2579 on NVD →
WowStore <= 4.2.4 - Missing Authorization
medium
The WooCommerce Builder & Gutenberg WooCommerce Blocks – WowStore plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform...
- CVSS:
- 4.3
- Affected:
- up to 4.2.4
- Fixed in:
- 4.2.5
- Disclosed:
- Apr 16, 2025
CVE-2025-39571 on NVD →
ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks <= 3.1.4 - PHP Object Injection via wopb_wishlist and wopb_compare
critical
The ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.4 via deserialization of untrusted input from the 'wopb_wishlist' and 'wopb_compare' cookies. This makes it possible for unauthenticated attackers to inj...
- CVSS:
- 9.8
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.5
- Disclosed:
- Jan 30, 2024
CVE-2024-23512 on NVD →
ProductX – Gutenberg WooCommerce Blocks <= 2.7.8 - Missing Authorization via option_data_save
medium
The ProductX – Gutenberg WooCommerce Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the option_data_save function in versions up to, and including, 2.7.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to m...
- CVSS:
- 4.3
- Affected:
- up to 2.7.8
- Fixed in:
- 3.0.0
- Disclosed:
- Oct 6, 2023
CVE-2023-45271 on NVD →
ProductX – Gutenberg WooCommerce Blocks – WooCommerce Builder, Wishlist for WooCommerce, Products Comparison, Quick View, Online Store – All in One Solution <= 2.2.5 - Multiple Cross-Site Scripting
medium
ProductX – Gutenberg WooCommerce Blocks – WooCommerce Builder, Wishlist for WooCommerce, Products Comparison, Quick View, Online Store – All in One Solution in versions up to and including 2.2.5 is vulnerable to Cross-Site Scripting due to insufficient sanitization and output escaping. This makes it possible for attack...
- CVSS:
- 6.1
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.6
- Disclosed:
- May 22, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database