plugin

Woo Bought Together Vulnerabilities

4 known security issues reported for the Woo Bought Together WordPress plugin. Most recent disclosed Nov 1, 2024.

2 medium

Running Woo Bought Together on your site? Check whether your installed version is affected.

Scan your site free

WPC Frequently Bought Together for WooCommerce [woo-bought-together] < 7.2.0

unknown

[en] Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.1.9.

Affected:
up to 7.2.0
Fixed in:
7.2.0
Disclosed:
Nov 1, 2024

CVE-2024-43312 on NVD →

WPC Frequently Bought Together for WooCommerce <= 7.1.9 - Missing Authorization

medium

The WPC Frequently Bought Together for WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the ajax_add_rule, ajax_add_combination, and ajax_search_term functions in versions up to, and including, 7.1.9. This makes it possible for authentic...

CVSS:
4.3
Affected:
up to 7.1.9
Fixed in:
7.2.0
Disclosed:
Aug 16, 2024

CVE-2024-43312 on NVD →

WPC Frequently Bought Together for WooCommerce [woo-bought-together] < 7.0.4

unknown

[en] Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.0.3.

Affected:
up to 7.0.4
Fixed in:
7.0.4
Disclosed:
Apr 22, 2024

CVE-2024-32687 on NVD →

WPC Frequently Bought Together for WooCommerce <= 7.0.3 - Missing Authorization

medium

The WPC Frequently Bought Together for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_get_search_results, ajax_import_export, and ajax_import_export_save functions in versions up to, and including, 7.0.3. This makes it possible for authenticated attac...

CVSS:
4.3
Affected:
up to 7.0.3
Fixed in:
7.0.4
Disclosed:
Apr 17, 2024

CVE-2024-32687 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database