Advance Search for WooCommerce [woo-advance-search] <= 2.0.3 (unfixed + closed)
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Advance Search for WooCommerce plugin (versions <= 2.0.3).
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 28, 2022
Advance Search for WooCommerce [woo-advance-search] <= 2.0.3 (unfixed + closed)
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress Advance Search for WooCommerce plugin (versions <= 2.0.3).
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 28, 2022
Advance Search for WooCommerce <= 1.0.9 - Cross-Site Scripting
medium
An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field, whi...
- CVSS:
- 6.1
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- May 30, 2018
CVE-2018-11486 on NVD →
Advance Search for WooCommerce < 1.1 - Cross-Site Scripting
medium
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
- CVSS:
- 6.1
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- May 30, 2018
CVE-2018-11485 on NVD →
Advance Search for WooCommerce [woo-advance-search] <= 2.0.3 (unfixed)
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database