Vulnerabilities and security researches forbrands-for-woocommerce brands-for-woocommerce
Direction: ascendingJun 07, 2024
Brands for WooCommerce # CVE-2023-23667
- CVE, Research URL
- Home page URL
- Application
- Date
- May 18, 2023
- Research Description
- Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions.
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable
Brands for WooCommerce # 978edf968cc1bb14ad6e4fc2a47804615027039d
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 13, 2022
- Research Description
- Brands for WooCommerce [brands-for-woocommerce] < 3.7.0.6 BeRocket Plugins <= (Various Versions) - Missing Authorization Several BeRocket Plugins for WordPress are vulnerable to authorization bypass due to missing capability checks on functions corresponding to AJAX actions that are available to subscribers. This includes the close_notice, subscribe, disable_rate_notice, feature_request_send, get_plugin_error_ajax, close_notice, and test_key functions This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those functions intended for administrator use. One of the functions is used to subscribe to the BeRocket newsletter and can be used by subscribers to subscribe arbitrary email addresses. These functions are still missing Cross-Site Request Forgery Protection.
- Affected versions
-
max 3.7.0.6.
- Status
-
vulnerable
Jun 10, 2024
Brands for WooCommerce # CVE-2023-44149
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 13, 2024
- Research Description
- Missing Authorization vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brands for WooCommerce: from n/a through <= 3.8.2.2.
- Affected versions
-
max 3.8.2.3.
- Status
-
vulnerable
Jan 10, 2026
Brands for WooCommerce # CVE-2025-68519
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 24, 2025
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Blind SQL Injection.This issue affects Brands for WooCommerce: from n/a through <= 3.8.6.3.
- Affected versions
-
max 3.8.6.4.
- Status
-
vulnerable
Jun 13, 2026
Brands for WooCommerce # CVE-2022-45813
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 11, 2026
- Research Description
- Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced AJAX Product Filters: from n/a through 1.6.3.3.
- Affected versions
-
max 3.7.0.6.
- Status
-
vulnerable
Jun 16, 2026
Brands for WooCommerce # 5392b1d5-57e1-4e4b-9a2a-bd46eaf3785b
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Brands for WooCommerce [brands-for-woocommerce] < 3.8.2.3 Brands for WooCommerce < 3.8.2.3 - Cross-Site Request Forgery The Brands for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.2.2. This is due to missing nonce validation on the clear_cache_ajax, save_order, and save_all_orders functions hooked via AJAX actions. This makes it possible for unauthenticated attackers to modify orders and clear the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 3.8.2.3.
- Status
-
vulnerable
Brands for WooCommerce # d3170ef65d2d07cdbff4d2a29c22edb189730cd6
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 22, 2023
- Research Description
- Brands for WooCommerce [brands-for-woocommerce] < 3.8.2.3 Brands for WooCommerce <= 3.8.2.2 - Missing Authorization to Unauthenticated Order Manipulation and Information Retrieval The Brands for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.8.2.2. This is due to missing capability checks on the clear_cache_ajax, save_order, br_get_products, br_get_brands, and save_all_orders functions hooked via AJAX nopriv actions. This makes it possible for unauthenticated attackers to modify orders and clear the plugin's cache. Please note that while the plugin author only added nonces to the functions, and not capability checks, the nonces are not disclosed to unauthorized users making this issue patched, though not perfectly.
- Affected versions
-
max 3.8.2.3.
- Status
-
vulnerable
Brands for WooCommerce # 0e772bb66f1b0db2aec19fe7ec48a3447c11bf25
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 22, 2023
- Research Description
- Brands for WooCommerce [brands-for-woocommerce] < 3.8.2.3 Brands for WooCommerce <= 3.8.2.2 - Cross-Site Request Forgery The Brands for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.2.2. This is due to missing nonce validation on the clear_cache_ajax, save_order, and save_all_orders functions hooked via AJAX actions. This makes it possible for unauthenticated attackers to modify orders and clear the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 3.8.2.3.
- Status
-
vulnerable
Jul 29, 2026
Brands for WooCommerce # CVE-2026-15648
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 24, 2026
- Research Description
- The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 3.8.8.1.
- Status
-
vulnerable
Brands for WooCommerce # CVE-2026-15647
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 23, 2026
- Research Description
- The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the payload is stored in term meta rather than post content, the WordPress unfiltered_html capability exception does not apply, meaning Shop Manager-level users — who normally lack unfiltered_html — can fully exploit this vulnerability.
- Affected versions
-
max 3.8.8.1.
- Status
-
vulnerable
Brands for WooCommerce # CVE-2026-15646
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 23, 2026
- Research Description
- The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 3.8.8.1.
- Status
-
vulnerable