XforWooCommerce [xforwoocommerce] <= 2.0.2 (unfixed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows PHP Local File Inclusion.This issue affects XforWooCommerce: from n/a through 2.0.2.
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 4, 2024
CVE-2024-33628 on NVD →
XforWooCommerce <= 2.0.2 - Authenticated (Subscriber+) Local File Inclusion
high
The XforWooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those fi...
- CVSS:
- 8.8
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 25, 2024
CVE-2024-33628 on NVD →
XforWooCommerce [xforwoocommerce] < 1.7.0
unknown
[en] Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or...
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Jun 7, 2023
CVE-2021-4337 on NVD →
XforWooCommerce [xforwoocommerce] < 1.7.0
unknown
Multiple vulnerabilities (Authenticated Arbitrary WordPress Options Change, Read and Deletion / Authenticated User Enumeration / Authenticated Plugin Settings Change, Import and Export) were discovered by Jerome Bruandet (NinTechNet) in the WordPress XforWooCommerce plugin (versions <=1.6.4).
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Sep 20, 2021
Multiple XforWooCommerce Add-On Plugins (Various Versions) - Missing Authorization
high
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or dele...
- CVSS:
- 8.8
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Sep 7, 2021
CVE-2021-4337 on NVD →
XforWooCommerce [xforwoocommerce] < 1.7.0
unknown
The svx_ajax_factory AJAX action of the plugins, available to authenticated users, do not have CSRF and capability checks, which could allow any authenticated user, such as subscriber to change/view/delete arbitrary WordPress options, retrieve the list of users, import/export/update the plugins' settings.
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database