Skip to main content

Vendor/product archive

villatheme / orders_tracking_for_woocommerce CVEs

Beta · best-effort

2 CVEs tagged to villatheme / orders_tracking_for_woocommerce0 Critical, 0 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2023-4216

Published Sep 4, 2023

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-25062

Published Jan 24, 2022

The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1