Vulnerabilities (CVE)

Filtered by vendor Xforwoocommerce
Filtered by product Add Product Tabs
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-4337 1 Xforwoocommerce 16 Add Product Tabs, Autopilot Seo, Bulk Add To Cart and 13 more 2024-11-21 N/A 8.8 HIGH
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or delete WordPress settings, plugin settings, and to arbitrarily list all users on a WordPress website. The plugins impacted are: Product Filter for WooCommerce < 8.2.0, Improved Product ...

Show More