VYPR

Wc Price History

by WordPress

Source repositories

CVEs (2)

  • CVE-2025-22510HigJan 9, 2025
    risk 0.48cvss 7.2epss 0.15

    Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affects WC Price History for Omnibus: from n/a through <= 2.1.4.

  • CVE-2024-12617MedDec 24, 2024
    risk 0.35cvss 5.4epss 0.00

    The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and modify history data.