plugin

Waitlist Woocommerce Vulnerabilities

11 known security issues reported for the Waitlist Woocommerce WordPress plugin. Most recent disclosed Nov 1, 2024.

2 high 3 medium

Running Waitlist Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.6.1

unknown

[en] Missing Authorization vulnerability in xootix Waitlist Woocommerce ( Back in stock notifier ) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Waitlist Woocommerce ( Back in stock notifier ): from n/a through 2.6.

Affected:
up to 2.6.1
Fixed in:
2.6.1
Disclosed:
Nov 1, 2024

CVE-2024-43134 on NVD →

Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.7.6

unknown

[en] The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to inject arbitrary web...

Affected:
up to 2.7.6
Fixed in:
2.7.6
Disclosed:
Sep 14, 2024

CVE-2024-8724 on NVD →

Waitlist Woocommerce ( Back in stock notifier ) <= 2.7.5 - Reflected Cross-Site Scripting

medium

The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
6.1
Affected:
up to 2.7.5
Fixed in:
2.7.6
Disclosed:
Sep 13, 2024

CVE-2024-8724 on NVD →

Waitlist Woocommerce ( Back in stock notifier ) <= 2.6 - Missing Authorization

medium

The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the send_email() and remove_row() function in versions up to, and including, 2.6. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
4.3
Affected:
up to 2.6
Fixed in:
2.6.1
Disclosed:
Aug 7, 2024

CVE-2024-43134 on NVD →

XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update

high

Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary optio...

CVSS:
8.8
Affected:
up to 2.6
Fixed in:
2.6.1
Disclosed:
Jun 5, 2024

CVE-2024-5324 on NVD →

Waitlist Woocommerce ( Back in stock notifier ) <= 2.5.2 - Cross-Site Request Forgery to Settings Reset

medium

The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. This is due to missing nonce validation on the reset_settings() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via...

CVSS:
4.3
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Jun 27, 2023

Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.5.3

unknown

The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. This is due to missing nonce validation on the reset_settings() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via...

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Jun 27, 2023

Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.5.3

unknown

Update the WordPress Waitlist WooCommerce ( Back in stock notifier ) plugin to the latest available version (at least 2.5.3). An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Waitlist Woocommerce ( Back in stock notifier ) Plugin. This could allow a malicious a...

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Jun 27, 2023

Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.5.2

unknown

[en] The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for...

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Jan 18, 2022

CVE-2022-0215 on NVD →

Waitlist Woocommerce ( Back in stock notifier ) <= 2.5.1 - Cross-Site Request Forgery to Arbitrary Options Update

high

The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for atta...

CVSS:
8.8
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
Jan 13, 2022

CVE-2022-0215 on NVD →

Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.5.3

unknown

The plugin does not have CSRF check when reseting its Settings, which could allow attackers to make logged in admins perform such action via a CSRF attack

Affected:
up to 2.5.3
Fixed in:
2.5.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database