WooCommerce Product Vendors

Vulnerabilities 15Slug woocommerce-product-vendors

Minimum safe version

2.2.3

Update to 2.2.3 or later to address 15 fixable vulnerabilities

Medium 4.7
2024-10-16< 2.0.36

CVE-2017-20193

Medium 5.3
2024-12-27< 2.2.2

WordPress WooCommerce Product Vendors Plugin <= 2.2.1 is vulnerable to Broken Access Control

Medium 5.3
2024-12-29< 2.2.3

WordPress WooCommerce Product Vendors Plugin <= 2.2.2 is vulnerable to Broken Access Control

N/A
< 2.0.36

WooCommerce Product Vendors Plugin &lt;= 2.0.27 - Unauthenticated Reflected XSS

N/A
< 2.1.66

WooCommerce Products Vendor &lt; 2.1.66 - Unauthenticated Blind SQLi

N/A
< 2.1.66

WooCommerce Products Vendor &lt; 2.1.66 - Note Creation via IDOR

N/A
< 2.1.69

WooCommerce Product Vendors &lt; 2.1.69 - Vendor Commission Percentage Update via IDOR

N/A
2022-10-04< 2.1.66

WooCommerce Products Vendor <= 2.1.65 - Insecure Direct Object Reference to Note Creation

N/A
2022-10-04< 2.1.69

WooCommerce Products Vendor <= 2.1.68 - Insecure Direct Object Reference to Vendor Commission Percentage Update

N/A
2022-10-04< 2.1.66

WooCommerce Products Vendor <= 2.1.65 - Unauthenticated SQL Injection

N/A
2017-08-22< 2.0.36

Product Vendors <= 2.0.35 - Reflected Cross Site Scripting

N/A
2017-08-31< 2.0.37

WordPress WooCommerce Product Vendors plugin <=2.0.27 - Unauthenticated Reflected XSS vulnerability