Subaccounts for WooCommerce [subaccounts-for-woocommerce] < 1.6.7
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce allows Authentication Abuse. This issue affects Subaccounts for WooCommerce: from n/a through 1.6.6.
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.7
- Disclosed:
- May 23, 2025
CVE-2025-47461 on NVD →
Subaccounts for WooCommerce <= 1.6.6 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover
high
The Subaccounts for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.6. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the sfwc_frontend_edit_subaccount_form_handl...
- CVSS:
- 8.8
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.7
- Disclosed:
- May 12, 2025
CVE-2025-47461 on NVD →
Subaccounts for WooCommerce [subaccounts-for-woocommerce] < 1.6.1
unknown
[en] The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Nov 21, 2024
CVE-2024-11370 on NVD →
Subaccounts for WooCommerce <= 1.6.0 - Reflected Cross-Site Scripting
medium
The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.1
- Disclosed:
- Nov 20, 2024
CVE-2024-11370 on NVD →
Subaccounts for WooCommerce [subaccounts-for-woocommerce] < 1.4.0
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.0
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database