Skip to main content

Vendor/product archive

automattic / woocommerce CVEs

Beta · best-effort

3 CVEs tagged to automattic / woocommerce0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-1310

Published Apr 15, 2024

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-17058

Published Nov 29, 2017

The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1