CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Villatheme 1Orders Tracking For Woocommerce Apr 23, 2025 Sep 4, 2023 N/A· v4 2.7 LOW· v3 N/A· v2 The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file...Show more |
1Villatheme 1Orders Tracking For Woocommerce Nov 21, 2024 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |