cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcost-of-goods-for-woocommerce cost-of-goods-for-woocommerce

Direction: ascending
Jun 06, 2024

Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce # 29b3b8593cdf8e737f3a04ff50cdb0c58cdc48b5

Date
Feb 06, 2023
Research Description
Cost of Goods Sold (COGS): Cost &amp; Profit Calculator for WooCommerce [cost-of-goods-for-woocommerce] < 2.8.7 WordPress Cost of Goods for WooCommerce Plugin <= 2.8.6 is vulnerable to Broken Access Control Update the WordPress Cost of Goods for WooCommerce plugin to the latest available version (at least 2.8.7). Cat discovered and reported this Broken Access Control vulnerability in WordPress Cost of Goods for WooCommerce Plugin. This vulnerability has been fixed in version 2.8.7.
Affected versions
Min -, max -.
Status
vulnerable

Cost of Goods Sold (COGS): Cost &amp; Profit Calculator for WooCommerce # CVE-2024-0821

CVE, Research URL

CVE-2024-0821

Date
Feb 29, 2024
Research Description
The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'section' parameter in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Cost of Goods Sold (COGS): Cost &amp; Profit Calculator for WooCommerce # CVE-2023-23868

CVE, Research URL

CVE-2023-23868

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in WPFactory Cost of Goods for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost of Goods for WooCommerce: from n/a through 2.8.6.
Affected versions
Min -, max -.
Status
vulnerable
Jun 02, 2025

Cost of Goods Sold (COGS): Cost &amp; Profit Calculator for WooCommerce # CVE-2025-48240

CVE, Research URL

CVE-2025-48240

Date
May 19, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Cost of Goods for WooCommerce allows Stored XSS. This issue affects Cost of Goods for WooCommerce: from n/a through 3.7.0.
Affected versions
Min -, max -.
Status
vulnerable