Docket [woocommerce-collections] < 1.7.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Aug 29, 2024
CVE-2024-43132 on NVD →
Docket [woocommerce-collections] < 1.7.0
unknown
[en] Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Aug 13, 2024
CVE-2024-43131 on NVD →
Docket (WooCommerce Collections / Wishlist / Watchlist) < 1.7.0 - Unauthenticated SQL Injection
critical
The Docket (WooCommerce Collections / Wishlist / Watchlist) plugin for WordPress is vulnerable to SQL Injection in versions up to 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to appen...
- CVSS:
- 10
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Aug 7, 2024
CVE-2024-43132 on NVD →
Docket (WooCommerce Collections / Wishlist / Watchlist) < 1.7.0 - Missing Authorization to Unauthenticated Arbitrary Post/Page Deletion
medium
The Docket (WooCommerce Collections / Wishlist / Watchlist) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.7.0 (exclusive). This makes it possible for unauthenticated attackers to delete arbitrary pages and posts.
- CVSS:
- 6.5
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Aug 7, 2024
CVE-2024-43131 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database