CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vanquish 1Woocommerce Support Ticket System Feb 24, 2025 Feb 1, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', 'ajax_get_customers_partial_list', and 'ajax...Show more |
1Vanquish 1Woocommerce Support Ticket System Jun 5, 2025 Nov 9, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including,...Show more |
1Vanquish 1Woocommerce Support Ticket System May 28, 2025 Nov 9, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function in all versions up to, and including, 17...Show more |
1Vanquish 1Woocommerce Support Ticket System May 28, 2025 Nov 9, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including...Show more |