cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foryayextra yayextra

Direction: ascending
Aug 04, 2024

YayExtra – WooCommerce Extra Product Options # CVE-2024-7257

CVE, Research URL

CVE-2024-7257

Date
Aug 03, 2024
Research Description
The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
Min -, max -.
Status
vulnerable
Apr 03, 2025

YayExtra – WooCommerce Extra Product Options # CVE-2025-31415

CVE, Research URL

CVE-2025-31415

Date
Apr 01, 2025
Research Description
Missing Authorization vulnerability in YayCommerce YayExtra allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YayExtra: from n/a through 1.5.2.
Affected versions
Min -, max -.
Status
vulnerable
Jul 18, 2025

YayExtra – WooCommerce Extra Product Options # CVE-2025-48299

CVE, Research URL

CVE-2025-48299

Date
Jul 16, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra allows SQL Injection. This issue affects YayExtra: from n/a through 1.5.5.
Affected versions
Min -, max -.
Status
vulnerable