YITH WooCommerce Product Add-Ons <= 4.29.0 - Authenticated (Shop manager+) SQL Injection
medium
The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.29.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manage...
- CVSS:
- 4.9
- Affected:
- up to 4.29.0
- Fixed in:
- 4.29.1
- Disclosed:
- May 20, 2026
CVE-2026-42383 on NVD →
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 4.2.1
unknown
[en] Missing Authorization vulnerability in YITH YITH WooCommerce Product Add-Ons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.2.0.
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.1
- Disclosed:
- Jan 2, 2025
CVE-2023-46635 on NVD →
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 4.14.2
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Reflected XSS.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.14.1.
- Affected:
- up to 4.14.2
- Fixed in:
- 4.14.2
- Disclosed:
- Oct 28, 2024
CVE-2024-50448 on NVD →
YITH WooCommerce Product Add-Ons <= 4.14.1 - Reflected Cross-Site Scripting
medium
The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.14.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
- CVSS:
- 6.1
- Affected:
- up to 4.14.1
- Fixed in:
- 4.14.2
- Disclosed:
- Oct 24, 2024
CVE-2024-50448 on NVD →
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 4.13.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Reflected XSS.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.13.0.
- Affected:
- up to 4.13.1
- Fixed in:
- 4.13.1
- Disclosed:
- Oct 6, 2024
CVE-2024-47367 on NVD →
YITH WooCommerce Product Add-Ons <= 4.13.0 - Reflected Cross-Site Scripting
medium
The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
- CVSS:
- 6.1
- Affected:
- up to 4.13.0
- Fixed in:
- 4.13.1
- Disclosed:
- Sep 30, 2024
CVE-2024-47367 on NVD →
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 4.9.3
unknown
[en] Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Code Injection.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.9.2.
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
- Disclosed:
- Jun 10, 2024
CVE-2024-35680 on NVD →
YITH WooCommerce Product Add-Ons <= 4.9.2 - Unauthenticated Content Injection
medium
The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Content Injection in all versions up to, and including, 4.9.2. This is due to the plugin not properly validating a field that can be updated. This makes it possible for unauthenticated attackers to inject arbitrary content.
- CVSS:
- 5.3
- Affected:
- up to 4.9.2
- Fixed in:
- 4.9.3
- Disclosed:
- Jun 6, 2024
CVE-2024-35680 on NVD →
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 4.6.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Reflected XSS.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.5.0.
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.0
- Disclosed:
- Mar 21, 2024
CVE-2024-27994 on NVD →
YITH WooCommerce Product Add-Ons <= 4.5.0 - Unuathenticated Cross-Site Scripting
medium
The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u...
- CVSS:
- 6.1
- Affected:
- up to 4.5.0
- Fixed in:
- 4.6.0
- Disclosed:
- Mar 15, 2024
CVE-2024-27994 on NVD →
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 4.3.1
unknown
[en] Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.1
- Disclosed:
- Dec 31, 2023
CVE-2023-49777 on NVD →
YITH WooCommerce Product Add-Ons <= 4.3.0 - Authenticated(Shop Manager+) PHP Object Injection
medium
The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 4.3.1 (exclusive) via deserialization of untrusted input in the 'save_addon' function. This makes it possible for authenticated attackers, with Shop Manager access and above, to inject a PHP Object. No...
- CVSS:
- 6.6
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.1
- Disclosed:
- Dec 28, 2023
CVE-2023-49777 on NVD →
YITH WooCommerce Product Add-Ons <= 4.2.0 - Missing Authorization
medium
The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to unauthorized functionality due to a missing capability check on two of its AJAX actions in versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to make use of this functionality and allows them to enable and...
- CVSS:
- 5.3
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.1
- Disclosed:
- Oct 25, 2023
CVE-2023-46635 on NVD →
YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization
high
Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the create_log_file function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the logs of the plugin which can contain sensitive information. Pl...
- CVSS:
- 7.1
- Affected:
- up to 2.15.0
- Fixed in:
- 2.16.0
- Disclosed:
- Nov 11, 2022
YITH plugins by YITHEMES <= (Various Versions) - Cross-Site Request Forgery
medium
Several YITHEMES plugins for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the create_log_file function. This makes it possible for unauthenticated attackers to create an error or debug log file using the plugin, via forged request granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 2.15.0
- Fixed in:
- 2.16.0
- Disclosed:
- Nov 11, 2022
CVE-2022-44630 on NVD →
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 2.16.0
unknown
Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the create_log_file function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the logs of the plugin which can contain sensitive information. Pl...
- Affected:
- up to 2.16.0
- Fixed in:
- 2.16.0
- Disclosed:
- Nov 11, 2022
YIT Plugin Framework <= 3.3.8 - Authenticated Settings Change
medium
Various versions of a various YITH WooCommerce plugins that use the YIT Plugin Framework through 3.3.8 are vulnerable to authorization bypass due to a missing capability check in the the 'save_toggle_element_options' function in .plugin-fw/lib/yit-plugin-panel-wc.php. This allows authenticated users with subscriber-lev...
- CVSS:
- 4.3
- Affected:
- up to 1.5.21
- Fixed in:
- 1.5.23
- Disclosed:
- Oct 31, 2019
CVE-2019-16251 on NVD →
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 1.5.23
unknown
[en] plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
- Affected:
- up to 1.5.23
- Fixed in:
- 1.5.23
- Disclosed:
- Oct 31, 2019
CVE-2019-16251 on NVD →
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 2.1.0
unknown
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.0
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 2.1.0
unknown
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.0
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 2.16.0
unknown
Update the WordPress YITH WooCommerce Product Add-Ons plugin to the latest available version (at least 2.16.0).
Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress YITH WooCommerce Product Add-Ons Plugin. This could allow a malicious actor to force higher privileged user...
- Affected:
- up to 2.16.0
- Fixed in:
- 2.16.0
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 2.16.0
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.16.0
- Fixed in:
- 2.16.0
CVE-2022-44630 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database