cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forstock-sync-for-woocommerce stock-sync-for-woocommerce

Direction: ascending
Jun 06, 2024

Stock Sync for WooCommerce # e16bba2b82e7a3b7f803839b899f413182f3c92b

Date
Mar 22, 2023
Research Description
Stock Sync for WooCommerce [stock-sync-for-woocommerce] < 2.4.1 WordPress Stock Sync for WooCommerce Plugin <= 2.3.2 is vulnerable to Broken Access Control No patched version is available. No reply from the vendor. Cat discovered and reported this Broken Access Control vulnerability in WordPress Stock Sync for WooCommerce Plugin. This vulnerability has not been known to be fixed yet.
Affected versions
max 2.4.1.
Status
vulnerable

Stock Sync for WooCommerce # CVE-2023-31094

CVE, Research URL

CVE-2023-31094

Date
Aug 18, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce plugin <= 2.4.0 versions.
Affected versions
max 2.4.1.
Status
vulnerable
Jun 10, 2024

Stock Sync for WooCommerce # CVE-2022-46807

CVE, Research URL

CVE-2022-46807

Date
Dec 13, 2024
Research Description
Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2.
Affected versions
max 2.4.0.
Status
vulnerable