plugin

Woocommerce Product Vendors Vulnerabilities

34 known security issues reported for the Woocommerce Product Vendors WordPress plugin. Most recent disclosed Oct 16, 2024.

1 critical 1 high 12 medium

Running Woocommerce Product Vendors on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.0.36

unknown

[en] The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

Affected:
up to 2.0.36
Fixed in:
2.0.36
Disclosed:
Oct 16, 2024

CVE-2017-20193 on NVD →

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.2.3

unknown

[en] Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.2.

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Jun 11, 2024

CVE-2023-52186 on NVD →

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.2.2

unknown

[en] Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1.

Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Jun 9, 2024

CVE-2023-51494 on NVD →

WooCommerce Product Vendors <= 2.2.2 - Missing Authorization

medium

The WooCommerce Product Vendors plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Dec 29, 2023

CVE-2023-52186 on NVD →

WooCommerce Product Vendors < 2.2.3 - Missing Authorization

medium
Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Dec 29, 2023

CVE-2023-52186 on NVD →

WooCommerce Product Vendors <= 2.2.1 - Missing Authorization

medium

The WooCommerce Product Vendors plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Dec 27, 2023

CVE-2023-51494 on NVD →

WooCommerce Product Vendors < 2.2.2 - Missing Authorization

medium
Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Dec 27, 2023

CVE-2023-51494 on NVD →

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.1.77

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76.

Affected:
up to 2.1.77
Fixed in:
2.1.77
Disclosed:
Dec 18, 2023

CVE-2023-33331 on NVD →

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.1.79

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.78.

Affected:
up to 2.1.79
Fixed in:
2.1.79
Disclosed:
Oct 31, 2023

CVE-2023-35879 on NVD →

WooCommerce Product Vendors < 2.1.77 - Reflected XSS

medium
Affected:
up to 2.1.77
Fixed in:
2.1.77
Disclosed:
Jun 21, 2023

CVE-2023-33332 on NVD →

WooCommerce Product Vendors < 2.1.77 - Vendor Admin+ SQLi

unknown
Affected:
up to 2.1.77
Fixed in:
2.1.77
Disclosed:
Jun 21, 2023

CVE-2023-33331 on NVD →

WooCommerce Product Vendors <= 2.1.78 - Authenticated (Shop manager+) SQL Injection

medium

The WooCommerce Product Vendors plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 2.1.78 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...

CVSS:
6.6
Affected:
up to 2.1.78
Fixed in:
2.1.79
Disclosed:
Jun 19, 2023

CVE-2023-35879 on NVD →

WooCommerce Product Vendors < 2.1.79 - ShopManager+ SQLi

unknown
Affected:
up to 2.1.79
Fixed in:
2.1.79
Disclosed:
Jun 19, 2023

CVE-2023-35879 on NVD →

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.1.77

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Product Vendors plugin <= 2.1.76 versions.

Affected:
up to 2.1.77
Fixed in:
2.1.77
Disclosed:
May 28, 2023

CVE-2023-33332 on NVD →

WooCommerce Product Vendors <= 2.1.76 - Authenticated (Vendor admin+) SQL Injection

high

The WooCommerce Product Vendors plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.76 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with vendor admin-le...

CVSS:
7.2
Affected:
up to 2.1.76
Fixed in:
2.1.77
Disclosed:
May 24, 2023

CVE-2023-33331 on NVD →

WooCommerce Product Vendors <= 2.1.76 - Reflected Cross-Site Scripting

medium

The WooCommerce Product Vendors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.1.76 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 2.1.76
Fixed in:
2.1.77
Disclosed:
May 24, 2023

CVE-2023-33332 on NVD →

WooCommerce Product Vendors < 2.1.77 - Unauthenticated Reflected XSS

medium
Affected:
up to 2.1.77
Fixed in:
2.1.77
Disclosed:
May 24, 2023

CVE-2023-33332 on NVD →

WooCommerce Product Vendors < 2.1.69 - Vendor Commission Percentage Update via IDOR

unknown
Affected:
up to 2.1.69
Fixed in:
2.1.69
Disclosed:
Nov 24, 2022

WooCommerce Products Vendor <= 2.1.65 - Unauthenticated SQL Injection

critical

The WooCommerce Products Vendor plugin for WordPress is vulnerable to blind SQL Injection via the ‘s_postcode’ parameter in versions up to, and including, 2.1.65 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthen...

CVSS:
9.8
Affected:
up to 2.1.65
Fixed in:
2.1.66
Disclosed:
Oct 4, 2022

WooCommerce Products Vendor <= 2.1.65 - Insecure Direct Object Reference to Note Creation

medium

The WooCommerce Products Vendor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.1.65. This is due to insufficient validation on the 'post_id' value supplied to the 'wc_product_vendors_vendor_add_order_note' AJAX action. This makes it possible for vendors to add...

CVSS:
4.3
Affected:
up to 2.1.65
Fixed in:
2.1.66
Disclosed:
Oct 4, 2022

WooCommerce Products Vendor <= 2.1.68 - Insecure Direct Object Reference to Vendor Commission Percentage Update

medium

The WooCommerce Products Vendor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.1.65. This is due to insufficient validation on the data supplied to the 'wcpv-vendor-settings' page settings update. This makes it possible for vendors to modify their commissions...

CVSS:
4.3
Affected:
up to 2.1.68
Fixed in:
2.1.69
Disclosed:
Oct 4, 2022

WooCommerce Products Vendor < 2.1.66 - Note Creation via IDOR

unknown
Affected:
up to 2.1.66
Fixed in:
2.1.66
Disclosed:
Oct 4, 2022

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.1.66

unknown

The WooCommerce Products Vendor plugin for WordPress is vulnerable to blind SQL Injection via the ‘s_postcode’ parameter in versions up to, and including, 2.1.65 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthen...

Affected:
up to 2.1.66
Fixed in:
2.1.66
Disclosed:
Oct 4, 2022

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.1.69

unknown

The WooCommerce Products Vendor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.1.65. This is due to insufficient validation on the data supplied to the 'wcpv-vendor-settings' page settings update. This makes it possible for vendors to modify their commissions...

Affected:
up to 2.1.69
Fixed in:
2.1.69
Disclosed:
Oct 4, 2022

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.1.66

unknown

The WooCommerce Products Vendor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.1.65. This is due to insufficient validation on the 'post_id' value supplied to the 'wc_product_vendors_vendor_add_order_note' AJAX action. This makes it possible for vendors to add...

Affected:
up to 2.1.66
Fixed in:
2.1.66
Disclosed:
Oct 4, 2022

WooCommerce Products Vendor < 2.1.66 - Unauthenticated Blind SQLi

unknown
Affected:
up to 2.1.66
Fixed in:
2.1.66
Disclosed:
Oct 4, 2022

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.0.37

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Ramuel Gall (SiteLock) on WordPress WooCommerce Product Vendors plugin version 2.0.27 and earlier versions. The plugin doesn't appear to escape the "vendor description" POST parameter correctly and can be exploited to reflect arbitrary scriptin...

Affected:
up to 2.0.37
Fixed in:
2.0.37
Disclosed:
Aug 31, 2017

Product Vendors <= 2.0.35 - Reflected Cross Site Scripting

medium

The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...

CVSS:
4.7
Affected:
up to 2.0.36
Fixed in:
2.0.36
Disclosed:
Aug 22, 2017

CVE-2017-20193 on NVD →

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.0.36

unknown

The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...

Affected:
up to 2.0.36
Fixed in:
2.0.36
Disclosed:
Aug 22, 2017

WooCommerce Product Vendors Plugin < 2.0.36 - Unauthenticated Reflected XSS

medium
Affected:
up to 2.0.36
Fixed in:
2.0.36
Disclosed:
Aug 22, 2017

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.1.69

unknown

The plugin does not ensure that vendors can not update the commission percentage set by shop admin, as a result, vendors can set their own commission percentage by making a crafted request

Affected:
up to 2.1.69
Fixed in:
2.1.69

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.1.66

unknown

The plugin does not ensure that notes to be created on an order belongs to the vendor doing it, allowing any vendor to create arbitrary note on other vendors&#039; orders via an IDOR

Affected:
up to 2.1.66
Fixed in:
2.1.66

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.1.66

unknown

The plugin does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

Affected:
up to 2.1.66
Fixed in:
2.1.66

WooCommerce Product Vendors [woocommerce-product-vendors] < 2.0.36

unknown

The woocommerce-product-vendors WordPress plugin was affected by an Unauthenticated Reflected XSS security vulnerability.

Affected:
up to 2.0.36
Fixed in:
2.0.36

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database