Vulnerabilities and security researches forgm-woocommerce-quote-popup gm-woocommerce-quote-popup
Direction: ascendingJun 07, 2024
Product Enquiry for WooCommerce # CVE-2023-47696
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 14, 2023
- Research Description
- Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.
- Affected versions
-
max 3.1.
- Status
-
vulnerable
Product Enquiry for WooCommerce # CVE-2023-49761
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 19, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0.
- Affected versions
-
max 3.1.
- Status
-
vulnerable
Product Enquiry for WooCommerce # CVE-2023-6626
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 23, 2024
- Research Description
- The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
max 3.1.
- Status
-
vulnerable
Product Enquiry for WooCommerce # CVE-2023-6625
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 23, 2024
- Research Description
- The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack
- Affected versions
-
max 3.1.
- Status
-
vulnerable
Product Enquiry for WooCommerce # CVE-2023-7151
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 16, 2024
- Research Description
- The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected versions
-
max 3.2.
- Status
-
vulnerable
Product Enquiry for WooCommerce # CVE-2023-47512
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 17, 2023
- Research Description
- Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.
- Affected versions
-
max 3.2.
- Status
-
vulnerable