Product Attachment for WooCommerce < 2.3.3 - Unauthenticated Information Exposure
medium
The Product Attachment for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 2.3.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Aug 2, 2026
CVE-2026-16285 on NVD →
WooCommerce Product Attachment <= 2.1.8 - Cross-Site Request Forgery
medium
The WooCommerce Product Attachment plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.8. This is due to missing nonce validation on the wcpoa_order_checkout_attachment_save() function. This makes it possible for unauthenticated attackers to save checkout page attachme...
- CVSS:
- 4.3
- Affected:
- up to 2.1.8
- Fixed in:
- 2.2.0
- Disclosed:
- Aug 11, 2023
CVE-2023-40212 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database