YITH WooCommerce Gift Cards Premium [yith-woocommerce-gift-cards-premium] < 3.24.0
unknown
[en] Missing Authorization vulnerability in YITH YITH WooCommerce Gift Cards Premium.This issue affects YITH WooCommerce Gift Cards Premium: from n/a through 3.23.1.
- Affected:
- up to 3.24.0
- Fixed in:
- 3.24.0
- Disclosed:
- Mar 21, 2024
CVE-2022-44633 on NVD →
YITH WooCommerce Gift Cards Premium <= 3.23.1 - Missing Authorization
medium
The YITH WooCommerce Gift Cards Premium plugin for WordPress is vulnerable to unauthorized gift card creation due to a missing capability check on one of its functions in versions up to, and including, 3.23.1. This makes it possible for unauthenticated attackers to create gift cards. Sanitization of user input is also...
- CVSS:
- 6.5
- Affected:
- up to 3.23.1
- Fixed in:
- 3.24.0
- Disclosed:
- May 10, 2023
CVE-2022-44633 on NVD →
YITH WooCommerce Gift Cards Premium [yith-woocommerce-gift-cards-premium] < 3.20.0
unknown
[en] Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
- Affected:
- up to 3.20.0
- Fixed in:
- 3.20.0
- Disclosed:
- Dec 6, 2022
CVE-2022-45359 on NVD →
Yith WooCommerce Gift Cards Premium <= 3.19.0 - Unauthenticated Arbitrary File Upload
critical
The Yith WooCommerce Gift Cards Premium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the import_actions_from_settings_panel function in versions up to, and including, 3.19.0. This makes it possible for unauthenticated attackers to upload arbit...
- CVSS:
- 9.8
- Affected:
- up to 3.19.0
- Fixed in:
- 3.20.0
- Disclosed:
- Nov 22, 2022
CVE-2022-45359 on NVD →
YITH WooCommerce Gift Cards Premium <= 3.3.0 - Arbitrary File Upload
critical
An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability, an attacker must be able to place a vali...
- CVSS:
- 9.8
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Jan 27, 2021
CVE-2021-3120 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database