WooCommerce Customers Manager [woocommerce-customers-manager] < 31.4
unknown
[en] The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new_roles() function in all versions up to, and including, 31.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate t...
- Affected:
- up to 31.4
- Fixed in:
- 31.4
- Disclosed:
- Feb 1, 2025
CVE-2024-13343 on NVD →
WooCommerce Customers Manager <= 31.3 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
high
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new_roles() function in all versions up to, and including, 31.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their...
- CVSS:
- 8.8
- Affected:
- up to 31.3
- Fixed in:
- 31.4
- Disclosed:
- Jan 31, 2025
CVE-2024-13343 on NVD →
WooCommerce Customers Manager [woocommerce-customers-manager] < 30.1
unknown
[en] The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks
- Affected:
- up to 30.1
- Fixed in:
- 30.1
- Disclosed:
- Aug 1, 2024
CVE-2024-3983 on NVD →
WooCommerce Customers Manager [woocommerce-customers-manager] < 30.1
unknown
[en] The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks
- Affected:
- up to 30.1
- Fixed in:
- 30.1
- Disclosed:
- Aug 1, 2024
CVE-2024-2843 on NVD →
WooCommerce Customers Manager [woocommerce-customers-manager] < 30.2
unknown
[en] The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said...
- Affected:
- up to 30.2
- Fixed in:
- 30.2
- Disclosed:
- Aug 1, 2024
CVE-2024-1747 on NVD →
WooCommerce Customers Manager <= 30.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The WooCommerce Customers Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'wccm_update_user_meta' in all versions up to, and including, 30.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to up...
- CVSS:
- 6.4
- Affected:
- up to 30.1
- Fixed in:
- 30.2
- Disclosed:
- Jul 11, 2024
CVE-2024-1747 on NVD →
WooCommerce Customers Manager < 30.1 - Cross-Site Request Forgery to Customer Deletion
medium
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 30.1 (exclusive). This is due to missing or incorrect nonce validation on the 'woocommerce-customers-manager' page. This makes it possible for unauthenticated attackers to delete customers via a forg...
- CVSS:
- 5.4
- Affected:
- up to 30.1
- Fixed in:
- 30.1
- Disclosed:
- Jul 11, 2024
CVE-2024-3983 on NVD →
WooCommerce Customers Manager < 30.1 - Cross-Site Request Forgery to Customer Deletion via 'Delete'
medium
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 30.1 (exclusive). This is due to missing or incorrect nonce validation on the 'woocommerce-customers-manager' page. This makes it possible for unauthenticated attackers to delete customers via a forg...
- CVSS:
- 5.4
- Affected:
- up to 30.1
- Fixed in:
- 30.1
- Disclosed:
- Jul 11, 2024
CVE-2024-2843 on NVD →
WooCommerce Customers Manager [woocommerce-customers-manager] < 29.8
unknown
[en] The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 29.8
- Fixed in:
- 29.8
- Disclosed:
- Apr 24, 2024
CVE-2024-1743 on NVD →
WooCommerce Customers Manager [woocommerce-customers-manager] < 29.8
unknown
[en] The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name
- Affected:
- up to 29.8
- Fixed in:
- 29.8
- Disclosed:
- Apr 24, 2024
CVE-2024-1756 on NVD →
WooCommerce Customers Manager [woocommerce-customers-manager] < 29.7
unknown
[en] The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.
- Affected:
- up to 29.7
- Fixed in:
- 29.7
- Disclosed:
- Apr 15, 2024
CVE-2024-0399 on NVD →
WooCommerce Customers Manager <= 29.7 - Reflected Cross-Site Scripting
medium
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 29.8 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 29.7
- Fixed in:
- 29.8
- Disclosed:
- Apr 3, 2024
CVE-2024-1743 on NVD →
WooCommerce Customers Manager <= 29.7 - Missing Authorization to Information Exposure
medium
The WooCommerce Customers Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wccm_get_customers_list AJAX action in all versions up to, and including, 29.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retr...
- CVSS:
- 4.3
- Affected:
- up to 29.7
- Fixed in:
- 29.8
- Disclosed:
- Apr 2, 2024
CVE-2024-1756 on NVD →
WooCommerce Customers Manager <= 29.6 - Authenticated (Subscriber+) SQL Injection
critical
The WooCommerce Customers Manager plugin for WordPress is vulnerable to SQL Injection via the 'max_amount_total' parameter in all versions up to, and including, 29.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for auth...
- CVSS:
- 9.9
- Affected:
- up to 29.6
- Fixed in:
- 29.7
- Disclosed:
- Mar 25, 2024
CVE-2024-0399 on NVD →
Woocommerce Customers Manager <= 26.5 - Cross-Site Request Forgery to Account Creation
high
The Woocommerce Customers Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 26.5. This makes it possible for unauthenticated attackers to create new accounts via forged request granted they can trick a site administrator into performing an action such as clicking...
- CVSS:
- 8.8
- Affected:
- up to 26.6
- Fixed in:
- 26.6
- Disclosed:
- Mar 30, 2021
Woocommerce Customers Manager < 26.6 - Reflected Cross-Site Scripting
medium
The Woocommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wccm_customers_ids’ and 'wccm_customers_emails' parameters in versions before 26.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- CVSS:
- 6.1
- Affected:
- up to 26.5
- Fixed in:
- 26.6
- Disclosed:
- Mar 30, 2021
WooCommerce Customers Manager [woocommerce-customers-manager] < 26.6
unknown
The Woocommerce Customers Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 26.5. This makes it possible for unauthenticated attackers to create new accounts via forged request granted they can trick a site administrator into performing an action such as clicking...
- Affected:
- up to 26.6
- Fixed in:
- 26.6
- Disclosed:
- Mar 30, 2021
WooCommerce Customers Manager [woocommerce-customers-manager] < 26.7
unknown
The Woocommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wccm_customers_ids’ and 'wccm_customers_emails' parameters in versions before 26.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- Affected:
- up to 26.7
- Fixed in:
- 26.7
- Disclosed:
- Mar 30, 2021
WooCommerce Customers Manager [woocommerce-customers-manager] < 26.7
unknown
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan Team in WordPress WooCommerce Customers Manager premium plugin (versions <= 26.6).
- Affected:
- up to 26.7
- Fixed in:
- 26.7
- Disclosed:
- Mar 30, 2021
Woocommerce Customers Manager <= 26.4 - Authenticated Account Creation and Privilege Escalation
high
The Woocommerce Customers Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability checks in the user import in versions up to, and including, 26.4. This makes it possible for Subscriber-level attackers to import arbitrary user information to create or update administrative account...
- CVSS:
- 8.8
- Affected:
- up to 26.5
- Fixed in:
- 26.5
- Disclosed:
- Feb 24, 2021
WooCommerce Customers Manager [woocommerce-customers-manager] < 26.5
unknown
The Woocommerce Customers Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability checks in the user import in versions up to, and including, 26.4. This makes it possible for Subscriber-level attackers to import arbitrary user information to create or update administrative account...
- Affected:
- up to 26.5
- Fixed in:
- 26.5
- Disclosed:
- Feb 24, 2021
WooCommerce Customers Manager [woocommerce-customers-manager] < 26.5
unknown
Privilege Escalation vulnerability discovered by John Castro (Pagely.com) in WordPress WooCommerce Customers Manager premium plugin (versions <= 26.4).
- Affected:
- up to 26.5
- Fixed in:
- 26.5
- Disclosed:
- Feb 24, 2021
WooCommerce Customers Manager [woocommerce-customers-manager] < 26.5
unknown
Cross-Site Scripting (XSS) vulnerability discovered by John Castro (Pagely.com) in WordPress WooCommerce Customers Manager premium plugin (versions <= 26.4).
- Affected:
- up to 26.5
- Fixed in:
- 26.5
- Disclosed:
- Feb 24, 2021
WooCommerce Customers Manager [woocommerce-customers-manager] < 26.6
unknown
The fixes for https://wpscan.com/vulnerability/126143e0-b0cc-4517-862e-3ac557db744f still allowed the issue to be performed via a CSRF attack.
The upload_csv AJAX action, available to authenticated users, did not have proper CRSF check, allowing attacker to make a logged in user with the manage_woocommerce capabilit...
- Affected:
- up to 26.6
- Fixed in:
- 26.6
WooCommerce Customers Manager [woocommerce-customers-manager] < 26.6
unknown
The wccm_customers_ids and wccm_customers_emails parameters are output in href attributes, after being sanitised with the sanitize_text_field() function, which is not appropriate for such case, as payload such as ' injected-attribute=value will still be injected. This lead to a reflected XSS issue in the administr...
- Affected:
- up to 26.6
- Fixed in:
- 26.6
WooCommerce Customers Manager [woocommerce-customers-manager] < 26.5
unknown
The upload_csv AJAX action, available to authenticated users, did not have proper capability checks. allowing any authenticated users, such as a subscriber, to call it and import arbitrary users. They could either update their own account, to make themselves administrator, or create new administrator accounts.
Note...
- Affected:
- up to 26.5
- Fixed in:
- 26.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database