plugin

Woo Advance Search Vulnerabilities

5 known security issues reported for the Woo Advance Search WordPress plugin. Most recent disclosed Feb 28, 2022.

2 medium

Running Woo Advance Search on your site? Check whether your installed version is affected.

Scan your site free

Advance Search for WooCommerce [woo-advance-search] <= 2.0.3 (unfixed + closed)

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Advance Search for WooCommerce plugin (versions <= 2.0.3).

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Feb 28, 2022

Advance Search for WooCommerce [woo-advance-search] <= 2.0.3 (unfixed + closed)

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Advance Search for WooCommerce plugin (versions <= 2.0.3).

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Feb 28, 2022

Advance Search for WooCommerce <= 1.0.9 - Cross-Site Scripting

medium

An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field, whi...

CVSS:
6.1
Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
May 30, 2018

CVE-2018-11486 on NVD →

Advance Search for WooCommerce < 1.1 - Cross-Site Scripting

medium

The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.

CVSS:
6.1
Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
May 30, 2018

CVE-2018-11485 on NVD →

Advance Search for WooCommerce [woo-advance-search] <= 2.0.3 (unfixed)

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.0.3
Fix:
No patched version reported

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database