cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foryith-woocommerce-product-add-ons yith-woocommerce-product-add-ons

Direction: ascending
Jun 07, 2024

YITH WooCommerce Product Add-Ons # CVE-2024-27994

CVE, Research URL

CVE-2024-27994

Date
Mar 21, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Reflected XSS.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.5.0.
Affected versions
max 4.6.0.
Status
vulnerable

YITH WooCommerce Product Add-Ons # CVE-2019-16251

CVE, Research URL

CVE-2019-16251

Date
Oct 31, 2019
Research Description
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
Affected versions
max 4.2.1.
Status
vulnerable

YITH WooCommerce Product Add-Ons # CVE-2023-49777

CVE, Research URL

CVE-2023-49777

Date
Dec 31, 2023
Research Description
Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.
Affected versions
max 4.3.1.
Status
vulnerable
Jun 10, 2024

YITH WooCommerce Product Add-Ons # CVE-2023-46635

CVE, Research URL

CVE-2023-46635

Date
Jan 02, 2025
Research Description
Missing Authorization vulnerability in YITH YITH WooCommerce Product Add-Ons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.2.0.
Affected versions
max 4.2.1.
Status
vulnerable
Jun 11, 2024

YITH WooCommerce Product Add-Ons # CVE-2024-35680

CVE, Research URL

CVE-2024-35680

Date
Jun 10, 2024
Research Description
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Code Injection.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.9.2.
Affected versions
max 4.9.3.
Status
vulnerable
Oct 04, 2024

YITH WooCommerce Product Add-Ons # CVE-2024-47367

CVE, Research URL

CVE-2024-47367

Date
Oct 06, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Reflected XSS.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.13.0.
Affected versions
max 4.13.1.
Status
vulnerable
Oct 28, 2024

YITH WooCommerce Product Add-Ons # CVE-2024-50448

CVE, Research URL

CVE-2024-50448

Date
-
Research Description
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] < 4.14.2 CVE-2024-50448
Affected versions
max 4.14.2.
Status
vulnerable
May 22, 2026

YITH WooCommerce Product Add-Ons # CVE-2026-42383

CVE, Research URL

CVE-2026-42383

Date
May 20, 2026
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection. This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.29.0.
Affected versions
max 4.29.1.
Status
vulnerable