VYPR

Product Specifications for Woocommerce

by WordPress

CVEs (2)

  • CVE-2022-46858HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Amin A.Rezapour Product Specifications for Woocommerce plugin <= 0.6.0 versions.

  • CVE-2026-11364Jun 27, 2026
    risk 0.00cvss epss 0.00

    The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. This is due to a missing capability check and missing nonce verification in the __invoke() methods of…