Openpos [woocommerce-openpos] < 7.0.2
unknown
[en] Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.
- Affected:
- up to 7.0.2
- Fixed in:
- 7.0.2
- Disclosed:
- Aug 13, 2024
CVE-2024-37935 on NVD →
Openpos [woocommerce-openpos] < 7.0.1
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in anhvnit Woocommerce OpenPos allows File Manipulation.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.1
- Disclosed:
- Jul 12, 2024
CVE-2024-37932 on NVD →
Openpos [woocommerce-openpos] < 7.0.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anhvnit Woocommerce OpenPos.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.1
- Disclosed:
- Jul 12, 2024
CVE-2024-37933 on NVD →
Woocommerce OpenPos <= 6.4.4 - Unauthenticated SQL Injection
critical
The Woocommerce OpenPos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL que...
- CVSS:
- 10
- Affected:
- up to 6.4.4
- Fixed in:
- 7.0.1
- Disclosed:
- Jul 9, 2024
CVE-2024-37933 on NVD →
Woocommerce OpenPos <= 6.4.4 - Unauthenticated Arbitrary File Deletion
critical
The Openpos - WooCommerce Point Of Sale(POS) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 6.4.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily le...
- CVSS:
- 9.1
- Affected:
- up to 6.4.4
- Fixed in:
- 7.0.1
- Disclosed:
- Jul 9, 2024
CVE-2024-37932 on NVD →
Woocommerce OpenPos <= 7.0.1 - Missing Authorization to Information Exposure
medium
The Woocommerce OpenPos plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a function in versions up to, and including, 7.0.1. This makes it possible for unauthenticated attackers to view sensitive information.
- CVSS:
- 5.3
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.2
- Disclosed:
- Jul 9, 2024
CVE-2024-37935 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database