User Email Verification for WooCommerce [woo-confirmation-email] <= 3.5.0 (unfixed + closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions.
- Affected:
- up to 3.5.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 4, 2023
CVE-2023-39162 on NVD →
User Email Verification for WooCommerce <= 3.5.0 - Reflected Cross-Site Scripting
medium
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 3.5.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 26, 2023
CVE-2023-39162 on NVD →
User Email Verification for WooCommerce <= 3.5.0 - Authentication Bypass
high
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to impersonat...
- CVSS:
- 8.1
- Affected:
- up to 3.5.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 2, 2023
CVE-2023-2781 on NVD →
User Email Verification for WooCommerce [woo-confirmation-email] <= 3.5.0 (unfixed + closed)
unknown
[en] The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to imper...
- Affected:
- up to 3.5.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 2, 2023
CVE-2023-2781 on NVD →
User Email Verification for WooCommerce [woo-confirmation-email] < 3.2.0 (closed)
unknown
[en] The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Aug 29, 2019
CVE-2018-21007 on NVD →
User Email Verification for WooCommerce <= 3.3.0 - Unauthenticated Arbitrary Options Update
high
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.3.0. This is due to missing authorization checks on the save_tab_settings() function. This makes it possible for unauthenticated attackers to change otherwise restricted plugin opti...
- CVSS:
- 8.8
- Affected:
- up to 3.3.0
- Fixed in:
- 3.4.0
- Disclosed:
- May 22, 2019
User Email Verification for WooCommerce [woo-confirmation-email] < 3.4.0 (closed)
unknown
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.3.0. This is due to missing authorization checks on the save_tab_settings() function. This makes it possible for unauthenticated attackers to change otherwise restricted plugin opti...
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.0
- Disclosed:
- May 22, 2019
Woo Confirmation Email < 3.2.0 - Improper Access Control
critical
The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.
- CVSS:
- 9.8
- Affected:
- up to 3.1.15
- Fixed in:
- 3.2.0
- Disclosed:
- Nov 27, 2018
CVE-2018-21007 on NVD →
User Email Verification for WooCommerce [woo-confirmation-email] < 3.4.0 (closed)
unknown
The User Email Verification for WooCommerce WordPress plugin was affected by a CSRF leading to Option Update security vulnerability.
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database