plugin

Spreadr For Woocomerce Vulnerabilities

4 known security issues reported for the Spreadr For Woocomerce WordPress plugin. Most recent disclosed Dec 18, 2024.

1 high 1 medium

Running Spreadr For Woocomerce on your site? Check whether your installed version is affected.

Scan your site free

Spreadr Woocommerce Plugin &#8211; Amazon Importer for Dropshipping and Affiliate [spreadr-for-woocomerce] < 1.0.5

unknown

[en] Missing Authorization vulnerability in spreadr Spreadr Woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Spreadr Woocommerce: from n/a through 1.0.4.

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Dec 18, 2024

CVE-2024-56008 on NVD →

Spreadr Woocommerce Plugin &#8211; Amazon Importer for Dropshipping and Affiliate [spreadr-for-woocomerce] < 1.0.5

unknown

[en] Missing Authorization vulnerability in spreadr Spreadr Woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Spreadr Woocommerce: from n/a through 1.0.4.

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Dec 16, 2024

CVE-2024-56009 on NVD →

Spreadr Woocommerce <= 1.0.4 - Missing Authorization to Arbitrary Content Deletion

high

The Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to perform arbitrary content deletio...

CVSS:
7.2
Affected:
up to 1.0.4
Fixed in:
1.0.5
Disclosed:
Dec 14, 2024

CVE-2024-56008 on NVD →

Spreadr Woocommerce <= 1.0.4 - Missing Authorization

medium

The Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized act...

CVSS:
6.5
Affected:
up to 1.0.4
Fixed in:
1.0.5
Disclosed:
Dec 14, 2024

CVE-2024-56009 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database