Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution
medium
The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This ma...
- CVSS:
- 6.5
- Affected:
- up to 3.20.5
- Fixed in:
- 3.20.6
- Disclosed:
- Apr 13, 2026
CVE-2026-2582 on NVD →
Germanized for WooCommerce <= 3.9.4 - Reflected Cross-Site Scripting
medium
The Germanized for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 3.9.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.5
- Disclosed:
- May 31, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database