VYPR

Bot For Telegram On Woocommerce

by WordPress

Source repositories

CVEs (2)

  • CVE-2024-9821HigOct 12, 2024
    risk 0.54cvss 8.8epss 0.01

    The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.7. This makes it possible for authenticated…

  • CVE-2025-48268MedMay 19, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in Guru Team Bot for Telegram on WooCommerce bot-for-telegram-on-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bot for Telegram on WooCommerce: from n/a through <= 1.2.6.