plugin

Wholesalex Vulnerabilities

8 known security issues reported for the Wholesalex WordPress plugin. Most recent disclosed May 17, 2024.

1 critical 3 medium

Running Wholesalex on your site? Check whether your installed version is affected.

Scan your site free

WholesaleX – WooCommerce Wholesale Plugin (B2B Wholesale Prices, Order Form, Catalog Mode, Tiered Pricing) [wholesalex] < 1.3.3

unknown

[en] Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects WholesaleX: from n/a through 1.3.2.

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
May 17, 2024

CVE-2024-30542 on NVD →

WholesaleX <= 1.3.2 - Unauthenticated Privilege Escalation

medium

The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.3.2. This makes it possible for unauthenticated attackers to escalate their privileges.

CVSS:
6.5
Affected:
up to 1.3.2
Fixed in:
1.3.3
Disclosed:
Mar 29, 2024

CVE-2024-30542 on NVD →

WholesaleX – WooCommerce Wholesale Plugin (B2B Wholesale Prices, Order Form, Catalog Mode, Tiered Pricing) [wholesalex] < 1.3.3

unknown

[en] Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Mar 28, 2024

CVE-2024-30224 on NVD →

WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) <= 1.3.2 - Unauthenticated PHP Object Injection

critical

The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No...

CVSS:
9.8
Affected:
up to 1.3.2
Fixed in:
1.3.3
Disclosed:
Mar 26, 2024

CVE-2024-30224 on NVD →

WholesaleX <= 1.3.1 - Authenticated(Subscriber+) Missing Authorization via multiple AJAX actions

medium

The WholesaleX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wc_install_callback AJAX function in versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to install woocommerce.

CVSS:
4.3
Affected:
up to 1.3.1
Fixed in:
1.3.2
Disclosed:
Mar 26, 2024

CVE-2024-30234 on NVD →

WholesaleX <= 1.3.1 - Sensitive Information Exposure via export_users

medium

The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the 'export_users'. This makes it possible for authenticated attackers, with access to the admin dashboar...

CVSS:
4.3
Affected:
up to 1.3.1
Fixed in:
1.3.2
Disclosed:
Mar 26, 2024

CVE-2024-30233 on NVD →

WholesaleX – WooCommerce Wholesale Plugin (B2B Wholesale Prices, Order Form, Catalog Mode, Tiered Pricing) [wholesalex] < 1.3.2

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.

Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Mar 26, 2024

CVE-2024-30233 on NVD →

WholesaleX – WooCommerce Wholesale Plugin (B2B Wholesale Prices, Order Form, Catalog Mode, Tiered Pricing) [wholesalex] < 1.3.2

unknown

[en] Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.

Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Mar 26, 2024

CVE-2024-30234 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database