CVE-2017-20193
WooCommerce Product Vendors
Minimum safe version
2.2.3
Update to 2.2.3 or later to address 15 fixable vulnerabilities
WordPress WooCommerce Product Vendors Plugin <= 2.2.1 is vulnerable to Broken Access Control
WordPress WooCommerce Product Vendors Plugin <= 2.2.2 is vulnerable to Broken Access Control
WooCommerce Product Vendors Plugin <= 2.0.27 - Unauthenticated Reflected XSS
WooCommerce Products Vendor < 2.1.66 - Unauthenticated Blind SQLi
WooCommerce Products Vendor < 2.1.66 - Note Creation via IDOR
WooCommerce Product Vendors < 2.1.69 - Vendor Commission Percentage Update via IDOR
WooCommerce Products Vendor <= 2.1.65 - Insecure Direct Object Reference to Note Creation
WooCommerce Products Vendor <= 2.1.68 - Insecure Direct Object Reference to Vendor Commission Percentage Update
WooCommerce Products Vendor <= 2.1.65 - Unauthenticated SQL Injection
CVE-2023-35879
CVE-2023-33331
CVE-2023-33332
Product Vendors <= 2.0.35 - Reflected Cross Site Scripting
WordPress WooCommerce Product Vendors plugin <=2.0.27 - Unauthenticated Reflected XSS vulnerability