Vulnerabilities (CVE)

Filtered by vendor Automattic Subscribe
Filtered by product Woocommerce
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-1310 1 Automattic 1 Woocommerce 2025-05-27 N/A 4.9 MEDIUM
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
CVE-2017-17058 1 Automattic 1 Woocommerce 2025-04-20 5.0 MEDIUM 7.5 HIGH
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traversal is not possible because all of the template files have "if (!defined('ABSPATH')) {exit;}" code
CVE-2023-47777 1 Automattic 2 Woocommerce, Woocommerce Blocks 2024-11-21 N/A 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.