Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist <= 3.0.6 - Authenticated (Subscriber+) Sensitive Information Exposure
medium
The Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuratio...
- CVSS:
- 4.3
- Affected:
- up to 3.0.6
- Fixed in:
- 3.1.0
- Disclosed:
- Jul 16, 2026
CVE-2026-61945 on NVD →
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist [woocommerce-product-stock-alert] < 2.0.2
unknown
[en] Missing Authorization vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Product Stock Alert: from n/a through 2.0.1.
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Dec 13, 2024
CVE-2023-37971 on NVD →
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist [woocommerce-product-stock-alert] < 2.0.2
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MultiVendorX Product Stock Manager & Notifier for WooCommerce.This issue affects Product Stock Manager & Notifier for WooCommerce: from n/a through 2.0.1.
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Nov 30, 2023
CVE-2023-37972 on NVD →
WooCommerce Product Stock Alert <= 2.0.1 - Information Disclosure
medium
The WooCommerce Product Stock Alert plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 2.0.1. This can allow attackers to extract information. The source of this vulnerability information, and data in the changeset, does not provide us with enough information to determine what...
- CVSS:
- 5.3
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Jul 12, 2023
CVE-2023-37972 on NVD →
WooCommerce Product Stock Alert <= 2.0.1 - Missing Authorization via API
medium
The WooCommerce Product Stock Alert plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stock_alert_rest_routes_react_module action in versions up to, and including, 2.0.1. This makes it possible for authenticated attackers with subscriber-level access to use this...
- CVSS:
- 5.4
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Jul 10, 2023
CVE-2023-37971 on NVD →
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist [woocommerce-product-stock-alert] < 2.0.2
unknown
The WooCommerce Product Stock Alert plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stock_alert_rest_routes_react_module action in versions up to, and including, 2.0.1. This makes it possible for authenticated attackers with subscriber-level access to use this...
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Jul 10, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database