cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwc-checkout-getnet wc-checkout-getnet

Direction: descending
May 19, 2025

Plugin Oficial – Getnet para WooCommerce # CVE-2025-1289

CVE, Research URL

CVE-2025-1289

Date
May 16, 2025
Research Description
The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable

Plugin Oficial – Getnet para WooCommerce # CVE-2025-1303

CVE, Research URL

CVE-2025-1303

Date
May 16, 2025
Research Description
The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.
Affected versions
Min -, max -.
Status
vulnerable
Apr 03, 2025

Plugin Oficial – Getnet para WooCommerce # CVE-2025-30906

CVE, Research URL

CVE-2025-30906

Date
Apr 02, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coffee Code Tech Plugin Oficial – Getnet para WooCommerce allows Reflected XSS. This issue affects Plugin Oficial – Getnet para WooCommerce: from n/a through 1.7.3.
Affected versions
Min -, max -.
Status
vulnerable