Vulnerabilities (CVE)

Filtered by vendor Automattic Subscribe
Filtered by product Woocommerce
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-1310 1 Automattic 1 Woocommerce 2025-05-27 N/A N/A
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
CVE-2017-17058 1 Automattic 1 Woocommerce 2024-08-05 5.0 MEDIUM 7.5 HIGH
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traversal is not possible because all of the template files have "if (!defined('ABSPATH')) {exit;}" code
CVE-2023-47777 1 Automattic 2 Woocommerce, Woocommerce Blocks 2023-12-05 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.