WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint
high
The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update_option() without any option-name...
- CVSS:
- 8
- Affected:
- up to 5.4.16
- Fixed in:
- 5.4.17
- Disclosed:
- Jul 23, 2026
CVE-2026-12736 on NVD →
WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce <= 5.4.1 - Authenticated (Contributor+) Arbitrary File Upload
high
The WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 5.4.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to...
- CVSS:
- 8.8
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.2
- Disclosed:
- May 29, 2026
CVE-2026-42748 on NVD →
WPify Woo Czech [wpify-woo] < 4.0.11
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPify s.R.O. WPify Woo Czech allows Reflected XSS.This issue affects WPify Woo Czech: from n/a through 4.0.10.
- Affected:
- up to 4.0.11
- Fixed in:
- 4.0.11
- Disclosed:
- May 3, 2024
CVE-2024-33946 on NVD →
WPify Woo Czech <= 4.0.10 - Reflected Cross-Site Scripting
medium
The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 4.0.10
- Fixed in:
- 4.0.11
- Disclosed:
- Apr 30, 2024
CVE-2024-33946 on NVD →
WPify Woo Czech [wpify-woo] < 4.0.9
unknown
[en] The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta function in all versions up to, and including, 4.0.8. This makes it possible for unauthenticated attackers to obtain shipping details for orders as long as the order...
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Feb 20, 2024
CVE-2024-1492 on NVD →
WPify Woo Czech <= 4.0.8 - Missing Authorization
medium
The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta function in all versions up to, and including, 4.0.8. This makes it possible for unauthenticated attackers to obtain shipping details for orders as long as the order numbe...
- CVSS:
- 5.3
- Affected:
- up to 4.0.8
- Fixed in:
- 4.0.9
- Disclosed:
- Feb 19, 2024
CVE-2024-1492 on NVD →
WPify Woo Czech <= 3.5.6 - Reflected Cross-Site Scripting
medium
The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of '$_SERVER['PHP_SELF']' with insufficient input sanitization and output escaping in versions up to, and including, 3.5.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 6.1
- Affected:
- up to 3.5.6
- Fixed in:
- 3.5.7
- Disclosed:
- May 16, 2022
WPify Woo Czech [wpify-woo] < 3.5.7
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress WPify Woo Czech plugin (versions <= 3.5.6).
Update the WordPress WPify Woo Czech plugin to the latest available version (at least 3.5.7).
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.7
- Disclosed:
- May 16, 2022
WPify Woo Czech [wpify-woo] < 3.5.7
unknown
The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of '$_SERVER['PHP_SELF']' with insufficient input sanitization and output escaping in versions up to, and including, 3.5.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.7
- Disclosed:
- May 16, 2022
WPify Woo Czech [wpify-woo] < 3.5.7
unknown
The plugin uses the Vies library v2.2.0, which has a sample file outputting $_SERVER['PHP_SELF'] in an attribute without being escaped first, leading to a Reflected Cross-Site Scripting. The issue is only exploitable when the web server has the PDO driver installed, and write access to the example directory (...
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database