VYPR

Advanced Woo Search

by Advanced Woo Search

CVEs (4)

  • CVE-2024-9796CriOct 10, 2024
    risk 0.64cvss 9.8epss 0.03

    The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

  • CVE-2020-12070HigApr 24, 2020
    risk 0.49cvss 7.5epss 0.02

    The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-search.php.

  • CVE-2024-0251MedJan 13, 2024
    risk 0.40cvss 6.1epss 0.00

    The Advanced Woo Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search parameter in all versions up to, and including, 2.96 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2023-2452MedJun 9, 2023
    risk 0.29cvss 4.4epss 0.01

    The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…