← Back

Woocommerce Affiliate

woocommerce_affiliate

Vendor: Yithemes • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yithemes
1Woocommerce Affiliate
Nov 21, 2024
Mar 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated atta...Show more
The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.Show less