CatalogX – Product Catalog Mode & Product Enquiry, Request Quote for WooCommerce, Wholesale Prices, B2B, Wholesale User Roles, Dynamic Pricing, Tired Pricing & More [woocommerce-catalog-enquiry] < 5.0.3
unknown
[en] Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.2.
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- Dec 9, 2024
CVE-2023-50899 on NVD →
CatalogX – Product Catalog Mode & Product Enquiry, Request Quote for WooCommerce, Wholesale Prices, B2B, Wholesale User Roles, Dynamic Pricing, Tired Pricing & More [woocommerce-catalog-enquiry] < 5.0.6
unknown
[en] Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.5.
- Affected:
- up to 5.0.6
- Fixed in:
- 5.0.6
- Disclosed:
- Jun 9, 2024
CVE-2024-25929 on NVD →
Product Catalog Enquiry for WooCommerce by MultiVendorX <= 5.0.5 - Cross-Site Request Forgery via REST API
medium
The Product Catalog Enquiry for WooCommerce by MultiVendorX plugin for WordPress is vulnerable to cross-site request forgery due to an improper capability check on the 'catalog_permission' function in versions up to, and including, 5.0.5. While the REST endpoints are only initialized for administrator users, the fact t...
- CVSS:
- 4.3
- Affected:
- up to 5.0.5
- Fixed in:
- 5.0.6
- Disclosed:
- Feb 20, 2024
CVE-2024-25929 on NVD →
CatalogX – Product Catalog Mode & Product Enquiry, Request Quote for WooCommerce, Wholesale Prices, B2B, Wholesale User Roles, Dynamic Pricing, Tired Pricing & More [woocommerce-catalog-enquiry] < 5.0.3
unknown
[en] The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- Dec 18, 2023
CVE-2023-5348 on NVD →
Product Catalog Mode For WooCommerce <= 5.0.2 - Unauthenticated Stored Cross-Site Scripting
high
The Product Catalog Mode For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_hover_background_color' parameter in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...
- CVSS:
- 7.2
- Affected:
- up to 5.0.2
- Fixed in:
- 5.0.3
- Disclosed:
- Nov 21, 2023
CVE-2023-5348 on NVD →
CatalogX – Product Catalog Mode & Product Enquiry, Request Quote for WooCommerce, Wholesale Prices, B2B, Wholesale User Roles, Dynamic Pricing, Tired Pricing & More [woocommerce-catalog-enquiry] < 5.0.3
unknown
Update the WordPress Product Catalog Enquiry plugin to the latest available version (at least 5.0.3).
Unknown discovered and reported this Broken Access Control vulnerability in WordPress Product Catalog Enquiry Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check...
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- Nov 7, 2023
Product Catalog Enquiry <= 5.0.2 - Missing Authorization
medium
The Product Catalog Mode For Woocommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to an improper capability check on the catalog_rest_routes_react_module REST endpoints in all versions up to 5.0.3 (exclusive). This makes it possible for unauthenticated attackers to view dat...
- CVSS:
- 6.5
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- Nov 3, 2023
CVE-2023-50899 on NVD →
Product Catalog Mode For Woocommerce <= 5.0.2 - Missing Authorization
medium
The Product Catalog Mode For Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the dismiss_mvx_catalog_servive_notice function in all versions up to 5.0.3 (exclusive). This makes it possible for authenticated attackers, with subscriber access and a...
- CVSS:
- 4.3
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- Nov 3, 2023
CatalogX – Product Catalog Mode & Product Enquiry, Request Quote for WooCommerce, Wholesale Prices, B2B, Wholesale User Roles, Dynamic Pricing, Tired Pricing & More [woocommerce-catalog-enquiry] < 5.0.3
unknown
The Product Catalog Mode For Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the dismiss_mvx_catalog_servive_notice function in all versions up to 5.0.3 (exclusive). This makes it possible for authenticated attackers, with subscriber access and a...
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- Nov 3, 2023
CatalogX – Product Catalog Mode & Product Enquiry, Request Quote for WooCommerce, Wholesale Prices, B2B, Wholesale User Roles, Dynamic Pricing, Tired Pricing & More [woocommerce-catalog-enquiry] < 5.0.3
unknown
The Product Catalog Mode For Woocommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to an improper capability check on the catalog_rest_routes_react_module REST endpoints in all versions up to 5.0.3 (exclusive). This makes it possible for unauthenticated attackers to view dat...
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- Nov 3, 2023
CatalogX – Product Catalog Mode & Product Enquiry, Request Quote for WooCommerce, Wholesale Prices, B2B, Wholesale User Roles, Dynamic Pricing, Tired Pricing & More [woocommerce-catalog-enquiry] < 3.1.0
unknown
[en] The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Aug 27, 2019
CVE-2017-18592 on NVD →
WC Catalog Enquiry <= 3.0.5 - Arbitrary File Upload
critical
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
- CVSS:
- 9.8
- Affected:
- up to 3.0.5
- Fixed in:
- 3.1.0
- Disclosed:
- Apr 20, 2017
CVE-2017-18592 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database