Skip to main content

Vendor archive

villatheme CVEs

Beta · best-effort

18 CVEs tagged to vendor villatheme1 Critical, 2 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2024-12861

Published Jan 30, 2025

The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via the 'viw2s_view_log' AJAX action…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8277

Published Sep 11, 2024

The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not pro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-50831

Published Dec 21, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY – Multi Currency for WooCommerce allows Stored XSS.This issu…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-48778

Published Dec 18, 2023

Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Product Size Chart For WooCommerce.This issue affects Product Size Chart For WooCommerce: from n/a through 1.1.5.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4216

Published Sep 4, 2023

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-30482

Published Aug 8, 2023

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in VillaTheme WPBulky plugin <= 1.0.10 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-4379

Published Jun 7, 2023

The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmc_bulk_fixed_price function in versions up to,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1037

Published Apr 18, 2022

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25062

Published Jan 24, 2022

The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1