plugin

Woo Gutenberg Products Block Vulnerabilities

10 known security issues reported for the Woo Gutenberg Products Block WordPress plugin. Most recent disclosed Nov 30, 2023.

2 high 2 medium

Running Woo Gutenberg Products Block on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce Blocks [woo-gutenberg-products-block] < 11.1.2 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.

Affected:
up to 11.1.2
Fixed in:
11.1.2
Disclosed:
Nov 30, 2023

CVE-2023-47777 on NVD →

WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image alt Attribute

medium

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a featured image 'alt' attribute in versions up to, and including, 8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...

CVSS:
6.4
Affected:
up to 11.1.1
Fixed in:
11.1.2
Disclosed:
Nov 15, 2023

CVE-2023-47777 on NVD →

WooCommerce Blocks [woo-gutenberg-products-block] < 5.5.1 (closed)

unknown

[en] woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against th...

Affected:
up to 5.5.1
Fixed in:
5.5.1
Disclosed:
Jul 26, 2021

CVE-2021-32789 on NVD →

WooCommerce Blocks [woo-gutenberg-products-block] < 5.5.1 (closed)

unknown

Unauthenticated SQL Injection (SQLi) vulnerability discovered in WordPress WooCommerce Blocks plugin (versions <= 5.5.0).

Affected:
up to 5.5.1
Fixed in:
5.5.1
Disclosed:
Jul 15, 2021

WooCommerce Blocks < 5.5 - Authenticated Blind SQL Injection

high

woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc...

CVSS:
8.8
Affected:
up to 2.5.15, 2.6 – 2.6.1, 2.7 – 2.7.1, 2.8 – 2.8, 2.9 – 2.9, 3.0 – 3.0, 3.1 – 3.1, 3.2 – 3.2, 3.3 – 3.3, 3.4 – 3.4, 3.5 – 3.5, 3.6 – 3.6, 3.7 – 3.7.1, 3.8 – 3.8, 3.9 – 3.9, 4.0 – 4.0, 4.1 – 4.1, 4.2 – 4.2, 4.3 – 4.3, 4.4 – 4.4.2, 4.5 – 4.5.2, 4.6 – 4.6, 4.7 – 4.7, 4.8 – 4.8, 4.9 – 4.9.1, 5.0 – 5.0, 5.1 – 5.1, 5.2 – 5.2, 5.3 – 5.3.1, 5.4 – 5.4, 5.5 – 5.5
Fixed in:
2.5.16
Disclosed:
Jul 3, 2021

CVE-2021-32789 on NVD →

WooCommerce Blocks [woo-gutenberg-products-block] < 3.7.1 (closed)

unknown

Guest Account Creation vulnerability found in WordPress WooCommerce Blocks plugin (versions <= 3.7.0).

Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Nov 6, 2020

WooCommerce Blocks <= 3.7.0 - Authorization Bypass

high

The WooCommerce Blocks plugins for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.7.0. This is due to insufficient validation on the account creation processes during checkout. This makes it possible for an unauthenticated attacker to register an account on WooCommerce sites even wh...

CVSS:
7.3
Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Nov 5, 2020

WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation

medium

The WooCommerce plugin for WordPress is vulnerable to unauthorized user account creation during checkout even when the “Allow customers to create an account during checkout” setting is disabled. was disabled due to missing authorization checks in versions up to and including 4.6.1. The WooCommerce Blocks plugin for Wor...

CVSS:
6.5
Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Nov 5, 2020

WooCommerce Blocks [woo-gutenberg-products-block] < 3.7.1 (closed)

unknown

The WooCommerce Blocks plugins for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.7.0. This is due to insufficient validation on the account creation processes during checkout. This makes it possible for an unauthenticated attacker to register an account on WooCommerce sites even wh...

Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Nov 5, 2020

WooCommerce Blocks [woo-gutenberg-products-block] < 3.7.1 (closed)

unknown

Versions of WooCommerce prior to 4.6.2 contain a vulnerability that allows guest users to create accounts during checkout even when the &quot;Allow customers to create an account during checkout&quot; setting is disabled. This vulnerability is being exploited by a bot to place spam orders and create user accounts that...

Affected:
up to 3.7.1
Fixed in:
3.7.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database