plugin

Woocommerce Collections Vulnerabilities

4 known security issues reported for the Woocommerce Collections WordPress plugin. Most recent disclosed Aug 29, 2024.

1 critical 1 medium

Running Woocommerce Collections on your site? Check whether your installed version is affected.

Scan your site free

Docket [woocommerce-collections] < 1.7.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Aug 29, 2024

CVE-2024-43132 on NVD →

Docket [woocommerce-collections] < 1.7.0

unknown

[en] Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Aug 13, 2024

CVE-2024-43131 on NVD →

Docket (WooCommerce Collections / Wishlist / Watchlist) < 1.7.0 - Unauthenticated SQL Injection

critical

The Docket (WooCommerce Collections / Wishlist / Watchlist) plugin for WordPress is vulnerable to SQL Injection in versions up to 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to appen...

CVSS:
10
Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Aug 7, 2024

CVE-2024-43132 on NVD →

Docket (WooCommerce Collections / Wishlist / Watchlist) < 1.7.0 - Missing Authorization to Unauthenticated Arbitrary Post/Page Deletion

medium

The Docket (WooCommerce Collections / Wishlist / Watchlist) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.7.0 (exclusive). This makes it possible for unauthenticated attackers to delete arbitrary pages and posts.

CVSS:
6.5
Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Aug 7, 2024

CVE-2024-43131 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database