plugin

Yith Woocommerce Ajax Search Vulnerabilities

13 known security issues reported for the Yith Woocommerce Ajax Search WordPress plugin. Most recent disclosed Oct 6, 2024.

3 high 3 medium

Running Yith Woocommerce Ajax Search on your site? Check whether your installed version is affected.

Scan your site free

YITH WooCommerce Ajax Search [yith-woocommerce-ajax-search] < 2.8.1

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Ajax Search allows SQL Injection.This issue affects YITH WooCommerce Ajax Search: from n/a through 2.8.0.

Affected:
up to 2.8.1
Fixed in:
2.8.1
Disclosed:
Oct 6, 2024

CVE-2024-47350 on NVD →

YITH WooCommerce Ajax Search <= 2.8.0 - Unauthenticated SQL Injection

high

The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...

CVSS:
7.5
Affected:
up to 2.8.0
Fixed in:
2.8.1
Disclosed:
Sep 30, 2024

CVE-2024-47350 on NVD →

YITH WooCommerce Ajax Search [yith-woocommerce-ajax-search] < 2.7.1

unknown

[en] YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
Sep 23, 2024

CVE-2024-7846 on NVD →

YITH WooCommerce Ajax Search <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 2.7.0
Fixed in:
2.7.1
Disclosed:
Sep 2, 2024

CVE-2024-7846 on NVD →

YITH WooCommerce Ajax Search [yith-woocommerce-ajax-search] < 2.4.1

unknown

[en] The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
May 24, 2024

CVE-2024-4455 on NVD →

YITH WooCommerce Ajax Search <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting

high

The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
7.2
Affected:
up to 2.4.0
Fixed in:
2.4.1
Disclosed:
May 23, 2024

CVE-2024-4455 on NVD →

YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization

high

Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the create_log_file function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the logs of the plugin which can contain sensitive information. Pl...

CVSS:
7.1
Affected:
up to 1.25.0
Fixed in:
1.25.1
Disclosed:
Nov 11, 2022

YITH plugins by YITHEMES <= (Various Versions) - Cross-Site Request Forgery

medium

Several YITHEMES plugins for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the create_log_file function. This makes it possible for unauthenticated attackers to create an error or debug log file using the plugin, via forged request granted they can trick...

CVSS:
4.3
Affected:
up to 1.25.0
Fixed in:
1.25.1
Disclosed:
Nov 11, 2022

CVE-2022-44630 on NVD →

YITH WooCommerce Ajax Search [yith-woocommerce-ajax-search] <= 1.25.0 (unfixed)

unknown

Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the create_log_file function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the logs of the plugin which can contain sensitive information. Pl...

Affected:
up to 1.25.0
Fix:
No patched version reported
Disclosed:
Nov 11, 2022

YIT Plugin Framework <= 3.3.8 - Authenticated Settings Change

medium

Various versions of a various YITH WooCommerce plugins that use the YIT Plugin Framework through 3.3.8 are vulnerable to authorization bypass due to a missing capability check in the the 'save_toggle_element_options' function in .plugin-fw/lib/yit-plugin-panel-wc.php. This allows authenticated users with subscriber-lev...

CVSS:
4.3
Affected:
up to 1.6.9
Fixed in:
1.7.1
Disclosed:
Oct 31, 2019

CVE-2019-16251 on NVD →

YITH WooCommerce Ajax Search [yith-woocommerce-ajax-search] < 1.7.1

unknown

[en] plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Oct 31, 2019

CVE-2019-16251 on NVD →

YITH WooCommerce Ajax Search [yith-woocommerce-ajax-search] < 1.25.1

unknown

Update the WordPress YITH WooCommerce Ajax Search plugin to the latest available version (at least 1.25.1). Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress YITH WooCommerce Ajax Search Plugin. This could allow a malicious actor to force higher privileged users to exe...

Affected:
up to 1.25.1
Fixed in:
1.25.1

YITH WooCommerce Ajax Search [yith-woocommerce-ajax-search] < 1.25.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.25.1
Fixed in:
1.25.1

CVE-2022-44630 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database