cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forgm-woocommerce-quote-popup gm-woocommerce-quote-popup

Direction: ascending
Jun 07, 2024

Product Enquiry for WooCommerce # CVE-2023-47696

CVE, Research URL

CVE-2023-47696

Date
Nov 14, 2023
Research Description
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.
Affected versions
max 3.1.
Status
vulnerable

Product Enquiry for WooCommerce # CVE-2023-49761

CVE, Research URL

CVE-2023-49761

Date
Dec 19, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0.
Affected versions
max 3.1.
Status
vulnerable

Product Enquiry for WooCommerce # CVE-2023-6626

CVE, Research URL

CVE-2023-6626

Date
Jan 23, 2024
Research Description
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 3.1.
Status
vulnerable

Product Enquiry for WooCommerce # CVE-2023-6625

CVE, Research URL

CVE-2023-6625

Date
Jan 23, 2024
Research Description
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack
Affected versions
max 3.1.
Status
vulnerable

Product Enquiry for WooCommerce # CVE-2023-7151

CVE, Research URL

CVE-2023-7151

Date
Jan 16, 2024
Research Description
The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
max 3.2.
Status
vulnerable

Product Enquiry for WooCommerce # CVE-2023-47512

CVE, Research URL

CVE-2023-47512

Date
Nov 17, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.
Affected versions
max 3.2.
Status
vulnerable