plugin

Woomotiv Vulnerabilities

7 known security issues reported for the Woomotiv WordPress plugin. Most recent disclosed Dec 6, 2025.

1 high 2 medium

Running Woomotiv on your site? Check whether your installed version is affected.

Scan your site free

Live Sales Notification for Woocommerce &#8211; Woomotiv [woomotiv] <= 3.6.3 (unfixed)

unknown

[en] The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woomotiv_limit' parameter in all versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

Affected:
up to 3.6.3
Fix:
No patched version reported
Disclosed:
Dec 6, 2025

CVE-2025-13137 on NVD →

Live Sales Notification for Woocommerce – Woomotiv <= 3.6.3 - Reflected Cross-Site Scripting

medium

The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woomotiv_limit' parameter in all versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

CVSS:
6.1
Affected:
up to 3.6.3
Fix:
No patched version reported
Disclosed:
Dec 5, 2025

CVE-2025-13137 on NVD →

Live Sales Notification for Woocommerce &#8211; Woomotiv [woomotiv] < 3.6.3

unknown

[en] The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woomotiv_seen_products_.*' cookie in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

Affected:
up to 3.6.3
Fixed in:
3.6.3
Disclosed:
Jan 7, 2025

CVE-2024-12416 on NVD →

Woomotiv <= 3.6.1 - Unauthenticated SQL Injection

high

The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woomotiv_seen_products_.*' cookie in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thi...

CVSS:
7.5
Affected:
up to 3.6.1
Fixed in:
3.6.3
Disclosed:
Jan 6, 2025

CVE-2024-12416 on NVD →

Live Sales Notification for Woocommerce &#8211; Woomotiv [woomotiv] < 3.5.0

unknown

[en] The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.3. This is due to missing or incorrect nonce validation on the 'ajax_cancel_review' function. This makes it possible for unauthenticated attackers to res...

Affected:
up to 3.5.0
Fixed in:
3.5.0
Disclosed:
Mar 20, 2024

CVE-2024-1325 on NVD →

Live Sales Notification for Woocommerce – Woomotiv <= 3.4.3 - Cross-Site Request Forgery via ajax_cancel_review

medium

The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.3. This is due to missing or incorrect nonce validation on the 'ajax_cancel_review' function. This makes it possible for unauthenticated attackers to reset th...

CVSS:
4.3
Affected:
up to 3.4.3
Fixed in:
3.5
Disclosed:
Mar 19, 2024

CVE-2024-1325 on NVD →

Live Sales Notification for Woocommerce &#8211; Woomotiv [woomotiv] < 3.4

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.4
Fixed in:
3.4

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database