VYPR

AR For Woocommerce

by WordPress

Source repositories

CVEs (4)

  • CVE-2024-50510CriOct 30, 2024
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects AR For Woocommerce: from n/a through <= 6.3.

  • CVE-2026-14352HigJul 3, 2026
    risk 0.42cvss 7.5epss 0.01

    The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can…

  • CVE-2022-2267MedAug 29, 2022
    risk 0.28cvss 4.3epss 0.01

    The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can…

  • CVE-2022-2556LowAug 29, 2022
    risk 0.18cvss 2.7epss 0.01

    The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan…