plugin

Woocommerce Products Quick View Vulnerabilities

5 known security issues reported for the Woocommerce Products Quick View WordPress plugin. Most recent disclosed Aug 15, 2023.

1 high 1 medium

Running Woocommerce Products Quick View on your site? Check whether your installed version is affected.

Scan your site free

Products Quick View for WooCommerce [woocommerce-products-quick-view] < 2.3.0

unknown

Update the WordPress Products Quick View for WooCommerce plugin to the latest available version (at least 2.3.0). Unknown discovered and reported this Broken Access Control vulnerability in WordPress Products Quick View for WooCommerce Plugin. A broken access control issue refers to a missing authorization, authenticat...

Affected:
up to 2.3.0
Fixed in:
2.3.0
Disclosed:
Aug 15, 2023

Products Quick View for WooCommerce <= 2.2.0 - Missing Authorization

medium

The Products Quick View for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the quick_view_prettyphoto_custom_template_load() and quick_view_custom_template_load() functions called via AJAX actions in versions up to, and including, 2.2.0. This makes it...

CVSS:
4.3
Affected:
up to 2.3.0
Fixed in:
2.3.0
Disclosed:
Aug 14, 2023

Products Quick View for WooCommerce [woocommerce-products-quick-view] < 2.3.0

unknown

The Products Quick View for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the quick_view_prettyphoto_custom_template_load() and quick_view_custom_template_load() functions called via AJAX actions in versions up to, and including, 2.2.0. This makes it...

Affected:
up to 2.3.0
Fixed in:
2.3.0
Disclosed:
Aug 14, 2023

a3 Lazy Load <= 2.6.0 - Cross-Site Request Forgery to Settings Reset

high

The following plugins for WordPress are vulnerable to Cross-Site Request Forgery: a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...

CVSS:
8.8
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Nov 2, 2022

Products Quick View for WooCommerce [woocommerce-products-quick-view] < 2.0.2

unknown

The following plugins for WordPress are vulnerable to Cross-Site Request Forgery: a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Nov 2, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database