Directsoftware
directsoftware
2 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Directsoftware 1Order Attachments For Woocommerce Jun 17, 2026 Feb 28, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory. This makes it possible for unauthenticat...Show more |
1Directsoftware 1Order Attachments For Woocommerce Jun 17, 2026 Oct 12, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. T...Show more |