WooCommerce Conversion Tracking <= 2.0.11 - Missing Authorization via wcct_install_happy_addons
medium
The WooCommerce Conversion Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcct_install_happy_addons' function in versions up to and including 2.0.11. This makes it possible for authenticated attackers, with subscriber access and above, to insta...
- CVSS:
- 4.3
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.12
- Disclosed:
- Jan 31, 2024
CVE-2024-24711 on NVD →
WooCommerce Conversion Tracking <= 2.0.11 - Missing Authorization
medium
The WooCommerce Conversion Tracking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.12
- Disclosed:
- Jan 3, 2024
CVE-2023-52217 on NVD →
Appsero <= 1.2.1 - Missing Authorization
medium
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...
- CVSS:
- 4.3
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.11
- Disclosed:
- Dec 16, 2022
Appsero <= 1.2.0 - Cross-Site Request Forgery
medium
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...
- CVSS:
- 4.3
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.11
- Disclosed:
- Dec 14, 2022
CVE-2022-47150 on NVD →
WooCommerce Conversion Tracking <= 2.0.4 - Cross-Site Request Forgery and Cross-Site Scripting
high
The WooCommerce Conversion Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery and Cross-Site Scripting in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping along with insufficient nonce validation on the wcct_save_settings() function. This makes it po...
- CVSS:
- 8.8
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jan 2, 2020
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database