Vulnerabilities and security researches foryayextra yayextra
Direction: ascendingAug 04, 2024
YayExtra – WooCommerce Extra Product Options # CVE-2024-7257
- CVE, Research URL
- Date
- Aug 03, 2024
- Research Description
- The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Apr 03, 2025
YayExtra – WooCommerce Extra Product Options # CVE-2025-31415
- CVE, Research URL
- Date
- Apr 01, 2025
- Research Description
- Missing Authorization vulnerability in YayCommerce YayExtra allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YayExtra: from n/a through 1.5.2.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jul 18, 2025
YayExtra – WooCommerce Extra Product Options # CVE-2025-48299
- CVE, Research URL
- Date
- Jul 16, 2025
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra allows SQL Injection. This issue affects YayExtra: from n/a through 1.5.5.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable