plugin

Woocommerce Predictive Search Vulnerabilities

10 known security issues reported for the Woocommerce Predictive Search WordPress plugin. Most recent disclosed Dec 13, 2024.

4 medium

Running Woocommerce Predictive Search on your site? Check whether your installed version is affected.

Scan your site free

Predictive Search for WooCommerce [woocommerce-predictive-search] < 5.8.1

unknown

[en] Missing Authorization vulnerability in a3rev Software WooCommerce Predictive Search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Predictive Search: from n/a through 5.8.0.

Affected:
up to 5.8.1
Fixed in:
5.8.1
Disclosed:
Dec 13, 2024

CVE-2023-32963 on NVD →

Predictive Search for WooCommerce [woocommerce-predictive-search] < 6.1.0

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in a3rev Software WooCommerce Predictive Search allows Reflected XSS.This issue affects WooCommerce Predictive Search: from n/a through 6.0.1.

Affected:
up to 6.1.0
Fixed in:
6.1.0
Disclosed:
Jul 20, 2024

CVE-2024-38669 on NVD →

WooCommerce Predictive Search <= 6.0.1 - Reflected Cross-Site Scripting

medium

The WooCommerce Predictive Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...

CVSS:
6.1
Affected:
up to 6.0.1
Fixed in:
6.1.0
Disclosed:
Jul 10, 2024

CVE-2024-38669 on NVD →

WooCommerce Predictive Search <= 5.8.0 - Missing Authorization via multiple AJAX actions

medium

The WooCommerce Predictive Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple ajax sync functions in versions up to, and including, 5.8.0. This makes it possible for unauthenticated attackers to sync various product search results such as categor...

CVSS:
5.3
Affected:
up to 5.8.0
Fixed in:
5.8.1
Disclosed:
May 18, 2023

CVE-2023-32963 on NVD →

WooCommerce Predictive Search <= 5.8.0 - Cross-Site Request Forgery via multiple AJAX actions

medium

The WooCommerce Predictive Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing nonce check on multiple ajax sync functions in versions up to, and including, 5.8.0. This makes it possible for unauthenticated attackers to sync various product search results such as categories a...

CVSS:
5.3
Affected:
up to 5.8.0
Fixed in:
5.8.1
Disclosed:
May 18, 2023

CVE-2023-32963 on NVD →

Predictive Search for WooCommerce [woocommerce-predictive-search] < 1.0.6

unknown

Update the plugin. Jason Flemming discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WooCommerce Predictive Search Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed...

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
May 15, 2023

Predictive Search for WooCommerce [woocommerce-predictive-search] < 1.0.6

unknown

This plugin is prone to a cross site scripting vulnerability in index.php rs parameter. Update the plugin.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
May 15, 2015

Predictive Search for WooCommerce <= 1.0.5 - Cross-Site Scripting

medium

The Predictive Search for WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the predictive search box in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that exe...

CVSS:
6.1
Affected:
up to 1.0.5
Fixed in:
1.0.6
Disclosed:
Nov 27, 2012

Predictive Search for WooCommerce [woocommerce-predictive-search] < 1.0.6

unknown

The Predictive Search for WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the predictive search box in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that exe...

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Nov 27, 2012

Predictive Search for WooCommerce [woocommerce-predictive-search] < 1.0.6

unknown

The Predictive Search for WooCommerce WordPress plugin was affected by an index.php rs Parameter XSS security vulnerability.

Affected:
up to 1.0.6
Fixed in:
1.0.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database