WholesaleX – WooCommerce Wholesale Plugin (B2B Wholesale Prices, Order Form, Catalog Mode, Tiered Pricing) [wholesalex] < 1.3.3
unknown
[en] Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects WholesaleX: from n/a through 1.3.2.
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- May 17, 2024
CVE-2024-30542 on NVD →
WholesaleX <= 1.3.2 - Unauthenticated Privilege Escalation
medium
The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.3.2. This makes it possible for unauthenticated attackers to escalate their privileges.
- CVSS:
- 6.5
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.3
- Disclosed:
- Mar 29, 2024
CVE-2024-30542 on NVD →
WholesaleX – WooCommerce Wholesale Plugin (B2B Wholesale Prices, Order Form, Catalog Mode, Tiered Pricing) [wholesalex] < 1.3.3
unknown
[en] Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Mar 28, 2024
CVE-2024-30224 on NVD →
WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) <= 1.3.2 - Unauthenticated PHP Object Injection
critical
The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No...
- CVSS:
- 9.8
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.3
- Disclosed:
- Mar 26, 2024
CVE-2024-30224 on NVD →
WholesaleX <= 1.3.1 - Authenticated(Subscriber+) Missing Authorization via multiple AJAX actions
medium
The WholesaleX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wc_install_callback AJAX function in versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to install woocommerce.
- CVSS:
- 4.3
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.2
- Disclosed:
- Mar 26, 2024
CVE-2024-30234 on NVD →
WholesaleX <= 1.3.1 - Sensitive Information Exposure via export_users
medium
The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the 'export_users'. This makes it possible for authenticated attackers, with access to the admin dashboar...
- CVSS:
- 4.3
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.2
- Disclosed:
- Mar 26, 2024
CVE-2024-30233 on NVD →
WholesaleX – WooCommerce Wholesale Plugin (B2B Wholesale Prices, Order Form, Catalog Mode, Tiered Pricing) [wholesalex] < 1.3.2
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Mar 26, 2024
CVE-2024-30233 on NVD →
WholesaleX – WooCommerce Wholesale Plugin (B2B Wholesale Prices, Order Form, Catalog Mode, Tiered Pricing) [wholesalex] < 1.3.2
unknown
[en] Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Mar 26, 2024
CVE-2024-30234 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database