Medium 6.1
2024-12-16< 3.5.9
CVE-2024-55996
Minimum safe version
3.5.9
Update to 3.5.9 or later to address 8 fixable vulnerabilities
CVE-2024-55996
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2023-44144
Payment gateway per Product for WooCommerce <= 3.2.7 - Reflected Cross-Site Scripting
WordPress Dreamfox Media Payment gateway per Product for Woocommerce Plugin < 3.2.7 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Dreamfox Media Payment gateway per Product for Woocommerce plugin < 3.1.6 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
WordPress Dreamfox Media Payment gateway per Product for Woocommerce plugin < 3.1.6 - Sensitive Information Disclosure vulnerability