Addify
addify
6 CVEs • 14 products
Products (14)
Click to collapseToggle
Products (14)
Click to collapse
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component. |
1Addify 10Abandoned Cart Recovery Advanced Free GiftsCheckout Fields Manager+7 moreNov 21, 2024 Jul 31, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through...Show more |
1Addify 1Role Based Pricing For Woocommerce May 1, 2025 Nov 7, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upl...Show more |
1Addify 1Role Based Pricing For Woocommerce May 1, 2025 Nov 7, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subsc...Show more |
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular...Show more |
1Addify 1Automatic User Roles Switcher May 6, 2025 Oct 31, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator |