Pluginus
pluginus
85 CVEs • 17 products
Products (17)
Click to collapseToggle
Products (17)
Click to collapse
CVEs (85)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pluginus 1Bear Woocommerce Bulk Editor And Products Manager Professional Apr 8, 2026 Oct 20, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible f...Show more |
1Pluginus 1Bear Woocommerce Bulk Editor And Products Manager Professional Apr 8, 2026 Oct 20, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This mak...Show more |
1Pluginus 1Bear Woocommerce Bulk Editor And Products Manager Professional Apr 8, 2026 Oct 20, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it...Show more |
1Pluginus 1Bear Woocommerce Bulk Editor And Products Manager Professional Apr 8, 2026 Oct 20, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination fun...Show more |
1Pluginus 1Bear Woocommerce Bulk Editor And Products Manager Professional Apr 8, 2026 Oct 20, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible fo...Show more |
1Pluginus 1Bear Woocommerce Bulk Editor And Products Manager Professional Apr 8, 2026 Oct 20, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possibl...Show more |
1Pluginus 1Bear Woocommerce Bulk Editor And Products Manager Professional Apr 8, 2026 Oct 18, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This make...Show more |
1Pluginus 1Wolf Wordpress Posts Bulk Editor And Products Manager Professional Nov 21, 2024 Oct 17, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions. |
1Pluginus 1Wolf Wordpress Posts Bulk Editor And Products Manager Professional Nov 21, 2024 Aug 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.6 versions. |
1Pluginus 1Wolf Wordpress Posts Bulk Editor And Manager Professional Nov 21, 2024 Jun 22, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions. |
1Pluginus 1Wordpress Currency Switcher Professional Apr 8, 2026 Jun 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insuff...Show more |
1Pluginus 1Wordpress Currency Switcher Professional Apr 8, 2026 Jun 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9....Show more |
1Pluginus 1Wordpress Currency Switcher Apr 8, 2026 Jun 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in ver...Show more |
1Pluginus 1Wordpress Currency Switcher Professional Apr 8, 2026 Jun 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9...Show more |
1Pluginus 1Bear Woocommerce Bulk Editor And Products Manager Professional Apr 28, 2026 May 28, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions. |
The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered b...Show more |
1Pluginus 1Wordpress Meta Data And Taxonomies Filter Feb 25, 2025 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can...Show more |
1Pluginus 1Husky Products Filter Professional For Woocommerce Mar 25, 2025 Feb 6, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. |
1Pluginus 1Fox Currency Switcher Professional For Woocommerce Apr 4, 2025 Jan 16, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored...Show more |
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run cod...Show more |