Woocommerce Vietnam Checkout [woo-vietnam-checkout] < 2.0.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lê Văn Toản Woocommerce Vietnam Checkout allows Stored XSS.This issue affects Woocommerce Vietnam Checkout: from n/a through 2.0.7.
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
- Disclosed:
- Feb 8, 2024
CVE-2024-24885 on NVD →
Woocommerce Vietnam Checkout <= 2.0.7 - Authenticated (Shop manager+) Stored Cross-Site Scripting
medium
The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $currency variable in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access, to inj...
- CVSS:
- 4.4
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.8
- Disclosed:
- Feb 5, 2024
CVE-2024-24885 on NVD →
Woocommerce Vietnam Checkout <= 2.0.8 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 4.4
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.8
- Disclosed:
- Jan 10, 2024
Woocommerce Vietnam Checkout [woo-vietnam-checkout] < 2.0.8
unknown
The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
- Disclosed:
- Jan 10, 2024
Woocommerce Vietnam Checkout [woo-vietnam-checkout] < 2.0.8
unknown
Update the WordPress Woocommerce Vietnam Checkout plugin to the latest available version (at least 2.0.8).
WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Woocommerce Vietnam Checkout Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects,...
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
- Disclosed:
- Jan 10, 2024
Woocommerce Vietnam Checkout [woo-vietnam-checkout] < 2.0.6
unknown
[en] The Woocommerce Vietnam Checkout WordPress plugin before 2.0.6 does not escape the custom shipping phone field no the checkout form leading to XSS
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Nov 27, 2023
CVE-2023-5325 on NVD →
Woocommerce Vietnam Checkout <= 2.0.5 - Unauthenticated Stored Cross-Site Scripting
high
The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom shipping phone number in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...
- CVSS:
- 7.2
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Nov 6, 2023
CVE-2023-5325 on NVD →
Woocommerce Vietnam Checkout [woo-vietnam-checkout] < 2.0.5
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Le Van Toan Woocommerce Vietnam Checkout plugin <= 2.0.4 versions.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Mar 27, 2023
CVE-2022-46843 on NVD →
Woocommerce Vietnam Checkout <= 2.0.4 - Reflected Cross-Site Scripting
medium
The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘from’ and 'to' parameters in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- CVSS:
- 6.1
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Dec 9, 2022
CVE-2022-46843 on NVD →
Woocommerce Vietnam Checkout [woo-vietnam-checkout] < 2.0.5
unknown
The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘from’ and 'to' parameters in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Dec 9, 2022
Woocommerce Vietnam Checkout [woo-vietnam-checkout] < 2.0.8
unknown
The plugin is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages...
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database