High 8.5
2025-12-26< 3.8.6.4
Brands for WooCommerce <= 3.8.6.3 - Authenticated (Contributor+) SQL Injection
Minimum safe version
3.8.6.4
Update to 3.8.6.4 or later to address 8 fixable vulnerabilities
Brands for WooCommerce <= 3.8.6.3 - Authenticated (Contributor+) SQL Injection
Brands for WooCommerce < 3.8.2.3 - Cross-Site Request Forgery
CVE-2023-44149
Brands for WooCommerce <= 3.8.2.2 - Cross-Site Request Forgery
Brands for WooCommerce <= 3.8.2.2 - Missing Authorization to Unauthenticated Order Manipulation and Information Retrieval
CVE-2023-23667
WordPress Brands for WooCommerce Plugin <= 3.7.0.5 is vulnerable to Broken Access Control
BeRocket Plugins <= (Various Versions) - Missing Authorization