VYPR

Woocommerce For Japan

by WordPress

Source repositories

CVEs (5)

  • CVE-2023-47698HigDec 9, 2024
    risk 0.49cvss 8.6epss 0.00

    Missing Authorization vulnerability in shohei.tanaka Japanized For WooCommerce woocommerce-for-japan allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Japanized For WooCommerce: from n/a through <= 2.6.4.

  • CVE-2023-0948MedMay 8, 2023
    risk 0.40cvss 6.1epss 0.01

    The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

  • CVE-2025-14886MedJan 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `order` REST API endpoint in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to mark any…

  • CVE-2025-48284MedMay 19, 2025
    risk 0.28cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in shohei.tanaka Japanized For WooCommerce woocommerce-for-japan allows Cross Site Request Forgery.This issue affects Japanized For WooCommerce: from n/a through <= 2.6.40.

  • CVE-2026-1305MedFeb 27, 2026
    risk 0.27cvss 5.3epss 0.00

    The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and including, 2.8.4. This is due to a flawed permission check in the `paidy_webhook_permission_check` function that unconditionally returns `true` when the webhook…