Products Quick View for WooCommerce [woocommerce-products-quick-view] < 2.3.0
unknown
Update the WordPress Products Quick View for WooCommerce plugin to the latest available version (at least 2.3.0).
Unknown discovered and reported this Broken Access Control vulnerability in WordPress Products Quick View for WooCommerce Plugin. A broken access control issue refers to a missing authorization, authenticat...
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Aug 15, 2023
Products Quick View for WooCommerce <= 2.2.0 - Missing Authorization
medium
The Products Quick View for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the quick_view_prettyphoto_custom_template_load() and quick_view_custom_template_load() functions called via AJAX actions in versions up to, and including, 2.2.0. This makes it...
- CVSS:
- 4.3
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Aug 14, 2023
Products Quick View for WooCommerce [woocommerce-products-quick-view] < 2.3.0
unknown
The Products Quick View for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the quick_view_prettyphoto_custom_template_load() and quick_view_custom_template_load() functions called via AJAX actions in versions up to, and including, 2.2.0. This makes it...
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Aug 14, 2023
a3 Lazy Load <= 2.6.0 - Cross-Site Request Forgery to Settings Reset
high
The following plugins for WordPress are vulnerable to Cross-Site Request Forgery:
a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...
- CVSS:
- 8.8
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Nov 2, 2022
Products Quick View for WooCommerce [woocommerce-products-quick-view] < 2.0.2
unknown
The following plugins for WordPress are vulnerable to Cross-Site Request Forgery:
a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Nov 2, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database