Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.6.1
unknown
[en] Missing Authorization vulnerability in xootix Waitlist Woocommerce ( Back in stock notifier ) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Waitlist Woocommerce ( Back in stock notifier ): from n/a through 2.6.
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Nov 1, 2024
CVE-2024-43134 on NVD →
Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.7.6
unknown
[en] The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to inject arbitrary web...
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.6
- Disclosed:
- Sep 14, 2024
CVE-2024-8724 on NVD →
Waitlist Woocommerce ( Back in stock notifier ) <= 2.7.5 - Reflected Cross-Site Scripting
medium
The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- CVSS:
- 6.1
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.6
- Disclosed:
- Sep 13, 2024
CVE-2024-8724 on NVD →
Waitlist Woocommerce ( Back in stock notifier ) <= 2.6 - Missing Authorization
medium
The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the send_email() and remove_row() function in versions up to, and including, 2.6. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 2.6
- Fixed in:
- 2.6.1
- Disclosed:
- Aug 7, 2024
CVE-2024-43134 on NVD →
XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
high
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary optio...
- CVSS:
- 8.8
- Affected:
- up to 2.6
- Fixed in:
- 2.6.1
- Disclosed:
- Jun 5, 2024
CVE-2024-5324 on NVD →
Waitlist Woocommerce ( Back in stock notifier ) <= 2.5.2 - Cross-Site Request Forgery to Settings Reset
medium
The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. This is due to missing nonce validation on the reset_settings() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via...
- CVSS:
- 4.3
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Jun 27, 2023
Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.5.3
unknown
The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. This is due to missing nonce validation on the reset_settings() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via...
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- Jun 27, 2023
Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.5.3
unknown
Update the WordPress Waitlist WooCommerce ( Back in stock notifier ) plugin to the latest available version (at least 2.5.3).
An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Waitlist Woocommerce ( Back in stock notifier ) Plugin. This could allow a malicious a...
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- Jun 27, 2023
Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.5.2
unknown
[en] The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for...
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Jan 18, 2022
CVE-2022-0215 on NVD →
Waitlist Woocommerce ( Back in stock notifier ) <= 2.5.1 - Cross-Site Request Forgery to Arbitrary Options Update
high
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for atta...
- CVSS:
- 8.8
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.2
- Disclosed:
- Jan 13, 2022
CVE-2022-0215 on NVD →
Waitlist Woocommerce ( Back in stock notifier ) [waitlist-woocommerce] < 2.5.3
unknown
The plugin does not have CSRF check when reseting its Settings, which could allow attackers to make logged in admins perform such action via a CSRF attack
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database