plugin

Woocommerce Pre Orders Vulnerabilities

11 known security issues reported for the Woocommerce Pre Orders WordPress plugin. Most recent disclosed Aug 30, 2023.

1 high 4 medium

Running Woocommerce Pre Orders on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce Pre-Orders [woocommerce-pre-orders] < 2.0.0

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <= 1.9.0 versions.

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Aug 30, 2023

CVE-2023-32802 on NVD →

WooCommerce Pre-Orders [woocommerce-pre-orders] < 2.0.1

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <= 2.0.0 versions.

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Aug 30, 2023

CVE-2023-32793 on NVD →

WooCommerce Pre-Orders [woocommerce-pre-orders] < 2.0.3

unknown

[en] The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jul 31, 2023

CVE-2023-3508 on NVD →

WooCommerce Pre-Orders [woocommerce-pre-orders] < 2.0.3

unknown

[en] The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jul 31, 2023

CVE-2023-3507 on NVD →

WooCommerce Pre-Orders <= 2.0.2 - Cross-Site Request Forgery to Order Cancellation

medium

The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to cancel pre-orders via a forged request granted they ca...

CVSS:
4.3
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Jul 10, 2023

CVE-2023-3507 on NVD →

WooCommerce Pre-Orders <= 2.0.2 - Cross-Site Request Forgery

medium

The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on several of its functions. This makes it possible for unauthenticated attackers to invoke these functions and perform actions such a...

CVSS:
4.3
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Jul 10, 2023

CVE-2023-3508 on NVD →

WooCommerce Pre-Orders <= 2.0.1 - Reflected Cross-Site Scripting

medium

The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Jun 26, 2023

WooCommerce Pre-Orders [woocommerce-pre-orders] < 2.0.2

unknown

The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Jun 26, 2023

WooCommerce Pre-Orders <= 1.9.0 - Unauthenticated Cross-Site Scripting

high

The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acces...

CVSS:
7.2
Affected:
up to 1.9.0
Fixed in:
2.0.0
Disclosed:
May 15, 2023

CVE-2023-32802 on NVD →

WooCommerce Pre-Orders <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
May 15, 2023

CVE-2023-32793 on NVD →

WooCommerce Pre-Orders [woocommerce-pre-orders] < 2.0.2

unknown

The plugin does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 2.0.2
Fixed in:
2.0.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database