plugin

Woo Confirmation Email Vulnerabilities

9 known security issues reported for the Woo Confirmation Email WordPress plugin. Most recent disclosed Sep 4, 2023.

1 critical 2 high 1 medium

Running Woo Confirmation Email on your site? Check whether your installed version is affected.

Scan your site free

User Email Verification for WooCommerce [woo-confirmation-email] <= 3.5.0 (unfixed + closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions.

Affected:
up to 3.5.0
Fix:
No patched version reported
Disclosed:
Sep 4, 2023

CVE-2023-39162 on NVD →

User Email Verification for WooCommerce <= 3.5.0 - Reflected Cross-Site Scripting

medium

The User Email Verification for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 3.5.0
Fix:
No patched version reported
Disclosed:
Jul 26, 2023

CVE-2023-39162 on NVD →

User Email Verification for WooCommerce <= 3.5.0 - Authentication Bypass

high

The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to impersonat...

CVSS:
8.1
Affected:
up to 3.5.0
Fix:
No patched version reported
Disclosed:
Jun 2, 2023

CVE-2023-2781 on NVD →

User Email Verification for WooCommerce [woo-confirmation-email] <= 3.5.0 (unfixed + closed)

unknown

[en] The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to imper...

Affected:
up to 3.5.0
Fix:
No patched version reported
Disclosed:
Jun 2, 2023

CVE-2023-2781 on NVD →

User Email Verification for WooCommerce [woo-confirmation-email] < 3.2.0 (closed)

unknown

[en] The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Aug 29, 2019

CVE-2018-21007 on NVD →

User Email Verification for WooCommerce <= 3.3.0 - Unauthenticated Arbitrary Options Update

high

The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.3.0. This is due to missing authorization checks on the save_tab_settings() function. This makes it possible for unauthenticated attackers to change otherwise restricted plugin opti...

CVSS:
8.8
Affected:
up to 3.3.0
Fixed in:
3.4.0
Disclosed:
May 22, 2019

User Email Verification for WooCommerce [woo-confirmation-email] < 3.4.0 (closed)

unknown

The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.3.0. This is due to missing authorization checks on the save_tab_settings() function. This makes it possible for unauthenticated attackers to change otherwise restricted plugin opti...

Affected:
up to 3.4.0
Fixed in:
3.4.0
Disclosed:
May 22, 2019

Woo Confirmation Email < 3.2.0 - Improper Access Control

critical

The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.

CVSS:
9.8
Affected:
up to 3.1.15
Fixed in:
3.2.0
Disclosed:
Nov 27, 2018

CVE-2018-21007 on NVD →

User Email Verification for WooCommerce [woo-confirmation-email] < 3.4.0 (closed)

unknown

The User Email Verification for WooCommerce WordPress plugin was affected by a CSRF leading to Option Update security vulnerability.

Affected:
up to 3.4.0
Fixed in:
3.4.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database