StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce <= 2.1.1 - Missing Authorization
medium
The StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to perform an unauthorized actio...
- CVSS:
- 5.3
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 10, 2026
CVE-2026-66466 on NVD →
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter
high
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This ma...
- CVSS:
- 7.2
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Jul 27, 2026
CVE-2026-13440 on NVD →
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action
medium
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and unauthenticated (wp_ajax_nopriv_) users and...
- CVSS:
- 5.3
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Jul 27, 2026
CVE-2026-13110 on NVD →
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action
medium
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes...
- CVSS:
- 5.3
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Jul 27, 2026
CVE-2026-15411 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database