plugin

Woofunnels Aero Checkout Vulnerabilities

3 known security issues reported for the Woofunnels Aero Checkout WordPress plugin. Most recent disclosed Dec 27, 2023.

3 medium

Running Woofunnels Aero Checkout on your site? Check whether your installed version is affected.

Scan your site free

FunnelKit Checkout <= 3.10.3 - Unauthenticated Arbitrary Content Deletion

medium

The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on an unknown function in all versions up to, and including, 3.10.3. This makes it possible for unauthenticated attackers, to delete arbitrary content.

CVSS:
6.5
Affected:
up to 3.10.3
Fixed in:
3.11.0
Disclosed:
Dec 27, 2023

CVE-2023-51672 on NVD →

FunnelKit Checkout <= 3.10.3 - Authenticated(Subscriber+) Missing Authorization to Arbitrary Plugin Activation

medium

The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in all versions up to, and including, 3.10.3. This makes it possible for authenticated attackers, with subscriber access and above, to activate arbitrary plugins.

CVSS:
4.3
Affected:
up to 3.10.3
Fixed in:
3.11.0
Disclosed:
Dec 27, 2023

CVE-2023-51670 on NVD →

FunnelKit Checkout <= 3.10.3 - Authenticated(Subscriber+) Missing Authorization to Settings Change

medium

The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in all versions up to, and including, 3.10.3. This makes it possible for authenticated attackers, with subscriber access and above, to change the plugin's settings.

CVSS:
4.3
Affected:
up to 3.10.3
Fixed in:
3.11.0
Disclosed:
Dec 27, 2023

CVE-2023-51671 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database