Skip to main content

Vendor archive

wpwebelite CVEs

Beta · best-effort

18 CVEs tagged to vendor wpwebelite5 Critical, 10 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-68547

Published Jan 5, 2026

Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fol…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64258

Published Dec 18, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Retrieve Embedded Sensitive Data.T…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-39472

Published Apr 16, 2025

Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56265

Published Dec 31, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Reflected XSS.…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54383

Published Dec 18, 2024

Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: fr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10114

Published Nov 5, 2024

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39650

Published Nov 1, 2024

Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouc…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43132

Published Aug 29, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQ…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-43131

Published Aug 13, 2024

Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39651

Published Aug 13, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooComme…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7503

Published Aug 12, 2024

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-39652

Published Aug 1, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6637

Published Jul 20, 2024

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of bru…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6636

Published Jul 20, 2024

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6635

Published Jul 20, 2024

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'wo…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37502

Published Jul 9, 2024

Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5871

Published Jun 15, 2024

The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5868

Published Jun 15, 2024

The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1