Skip to main content

Vendor archive

storeapps CVEs

Beta · best-effort

8 CVEs tagged to vendor storeapps0 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2023-5663

Published Mar 13, 2024

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0566

Published Feb 12, 2024

The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by hi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36284

Published Aug 5, 2022

Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Paym…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34619

Published Jul 21, 2021

The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1