plugin

Yikes Inc Easy Custom Woocommerce Product Tabs Vulnerabilities

6 known security issues reported for the Yikes Inc Easy Custom Woocommerce Product Tabs WordPress plugin. Most recent disclosed Jan 7, 2025.

1 high 2 medium

Running Yikes Inc Easy Custom Woocommerce Product Tabs on your site? Check whether your installed version is affected.

Scan your site free

Custom Product Tabs for WooCommerce [yikes-inc-easy-custom-woocommerce-product-tabs] < 1.8.6

unknown

[en] The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input in the 'yikes_woo_products_tabs' post meta parameter. This makes it possible for authenticated attackers, with Shop Manager-level acc...

Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Jan 7, 2025

CVE-2024-11465 on NVD →

Custom Product Tabs for WooCommerce <= 1.8.5 - Authenticated (Shop Manager+) PHP Object Injection

high

The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input in the 'yikes_woo_products_tabs' post meta parameter. This makes it possible for authenticated attackers, with Shop Manager-level access a...

CVSS:
7.2
Affected:
up to 1.8.5
Fixed in:
1.8.6
Disclosed:
Jan 6, 2025

CVE-2024-11465 on NVD →

Custom Product Tabs for WooCommerce [yikes-inc-easy-custom-woocommerce-product-tabs] < 1.8.0

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Custom Product Tabs for WooCommerce plugin <= 1.7.9 on WordPress.

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Nov 18, 2022

CVE-2022-43463 on NVD →

Custom Product Tabs for WooCommerce <= 1.7.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Custom Product Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web script...

CVSS:
5.5
Affected:
up to 1.7.9
Fixed in:
1.8.0
Disclosed:
Oct 30, 2022

CVE-2022-43463 on NVD →

Custom Product Tabs for WooCommerce [yikes-inc-easy-custom-woocommerce-product-tabs] < 1.7.9

unknown

[en] Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.

Affected:
up to 1.7.9
Fixed in:
1.7.9
Disclosed:
Jul 21, 2022

CVE-2022-28666 on NVD →

Custom Product Tabs for WooCommerce <= 1.7.7 - Subscriber+ Settings Update

medium

The WordPress plugin Custom Product Tabs for WooCommerce is vulnerable to unauthenticated options update due to lack of authorization in the register_rest_route function in versions up to, and including 1.7.7. This allows an attacker to change the plugin's options.

CVSS:
6.3
Affected:
up to 1.7.7
Fixed in:
1.7.8
Disclosed:
Jun 28, 2022

CVE-2022-28666 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database