← Back

Variation Swatches For Woocommerce

variation_swatches_for_woocommerce

Vendor: Variation Swatches For Woocommerce Project • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Variation Swatches For Woocommerce Project
1Variation Swatches For Woocommerce
Feb 5, 2025
Jan 23, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the se...Show more
The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the URL. The related delete_settings() function performs a faulty nonce validation check, making the reset operation insecure and susceptible to unauthorized access.Show less
1Variation Swatches For Woocommerce Project
1Variation Swatches For Woocommerce
Nov 21, 2024
Jul 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Swatches for WooCommerce plugin <= 2.3.7 versions.
1Variation Swatches For Woocommerce Project
1Variation Swatches For Woocommerce
Nov 21, 2024
Dec 14, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/class-menu-page.php file which allows attackers to inject arbitrary web...Show more
The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/class-menu-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1. Due to missing authorization checks on the tawcvs_save_settings function, low-level authenticated users such as subscribers can exploit this vulnerability.Show less