Ppom For Woocommerce
by Najeebmedia
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25018 | Med | 0.35 | 5.4 | 0.01 | Feb 14, 2022 | The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation and escaping, it could… | ||
| CVE-2019-14948 | Med | 0.35 | 5.4 | 0.01 | Aug 12, 2019 | The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure. |
- risk 0.35cvss 5.4epss 0.01
The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation and escaping, it could…
- risk 0.35cvss 5.4epss 0.01
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.