cleantalk
Vulnerabilities and Security Researches

Security reports forserial-codes-generator-and-validator serial-codes-generator-and-validator

CVE/PSC Application Date Affected versions Description
Actual on: Jul 16, 2025, 08:07:20
Entries count: 3

CVE-2025-30854

Serial Codes Generator and Validator with WooCommerce Support

vulnerable

Apr 03, 2025, 01:04:17
Min -
Max 2.7.8
Cross-Site Request Forgery (CSRF) vulnerability in Saso Serial Codes Generator and Validator with WooCommerce Support allows Cross Site Request Forgery. This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through 2.7.7.

CVE-2023-4376

Serial Codes Generator and Validator with WooCommerce Support

vulnerable

Jun 07, 2024, 01:06:06
Min -
Max 2.4.15
The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

ba6efb0a623380b705452ba37eb8f74b11aae946

Serial Codes Generator and Validator with WooCommerce Support

vulnerable

Jun 07, 2024, 01:06:06
Min -
Max 2.4.15
Serial Codes Generator and Validator with WooCommerce Support [serial-codes-generator-and-validator] < 2.4.15 Serial Codes Generator and Validator with WooCommerce Support <= 2.4.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting The Serial Codes Generator and Validator with WooCommerce Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data[codes]' parameter saved through the sngmbhSerialcodesValidator_executeAdminSettings AJAX action in versions up to, and inc...