Custom Product Tabs for WooCommerce [yikes-inc-easy-custom-woocommerce-product-tabs] < 1.8.6
unknown
[en] The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input in the 'yikes_woo_products_tabs' post meta parameter. This makes it possible for authenticated attackers, with Shop Manager-level acc...
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Jan 7, 2025
CVE-2024-11465 on NVD →
Custom Product Tabs for WooCommerce <= 1.8.5 - Authenticated (Shop Manager+) PHP Object Injection
high
The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input in the 'yikes_woo_products_tabs' post meta parameter. This makes it possible for authenticated attackers, with Shop Manager-level access a...
- CVSS:
- 7.2
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.6
- Disclosed:
- Jan 6, 2025
CVE-2024-11465 on NVD →
Custom Product Tabs for WooCommerce [yikes-inc-easy-custom-woocommerce-product-tabs] < 1.8.0
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Custom Product Tabs for WooCommerce plugin <= 1.7.9 on WordPress.
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Nov 18, 2022
CVE-2022-43463 on NVD →
Custom Product Tabs for WooCommerce <= 1.7.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Custom Product Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web script...
- CVSS:
- 5.5
- Affected:
- up to 1.7.9
- Fixed in:
- 1.8.0
- Disclosed:
- Oct 30, 2022
CVE-2022-43463 on NVD →
Custom Product Tabs for WooCommerce [yikes-inc-easy-custom-woocommerce-product-tabs] < 1.7.9
unknown
[en] Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9
- Disclosed:
- Jul 21, 2022
CVE-2022-28666 on NVD →
Custom Product Tabs for WooCommerce <= 1.7.7 - Subscriber+ Settings Update
medium
The WordPress plugin Custom Product Tabs for WooCommerce is vulnerable to unauthenticated options update due to lack of authorization in the register_rest_route function in versions up to, and including 1.7.7. This allows an attacker to change the plugin's options.
- CVSS:
- 6.3
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.8
- Disclosed:
- Jun 28, 2022
CVE-2022-28666 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database