plugin

Xforwoocommerce Vulnerabilities

6 known security issues reported for the Xforwoocommerce WordPress plugin. Most recent disclosed Jun 4, 2024.

2 high

Running Xforwoocommerce on your site? Check whether your installed version is affected.

Scan your site free

XforWooCommerce [xforwoocommerce] <= 2.0.2 (unfixed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows PHP Local File Inclusion.This issue affects XforWooCommerce: from n/a through 2.0.2.

Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Jun 4, 2024

CVE-2024-33628 on NVD →

XforWooCommerce <= 2.0.2 - Authenticated (Subscriber+) Local File Inclusion

high

The XforWooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those fi...

CVSS:
8.8
Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Apr 25, 2024

CVE-2024-33628 on NVD →

XforWooCommerce [xforwoocommerce] < 1.7.0

unknown

[en] Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or...

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Jun 7, 2023

CVE-2021-4337 on NVD →

XforWooCommerce [xforwoocommerce] < 1.7.0

unknown

Multiple vulnerabilities (Authenticated Arbitrary WordPress Options Change, Read and Deletion / Authenticated User Enumeration / Authenticated Plugin Settings Change, Import and Export) were discovered by Jerome Bruandet (NinTechNet) in the WordPress XforWooCommerce plugin (versions <=1.6.4).

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Sep 20, 2021

Multiple XforWooCommerce Add-On Plugins (Various Versions) - Missing Authorization

high

Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or dele...

CVSS:
8.8
Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Sep 7, 2021

CVE-2021-4337 on NVD →

XforWooCommerce [xforwoocommerce] < 1.7.0

unknown

The svx_ajax_factory AJAX action of the plugins, available to authenticated users, do not have CSRF and capability checks, which could allow any authenticated user, such as subscriber to change/view/delete arbitrary WordPress options, retrieve the list of users, import/export/update the plugins&#039; settings.

Affected:
up to 1.7.0
Fixed in:
1.7.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database