Filtered by vendor Yithemes
Subscriptions
Filtered by product Woocommerce Affiliate
Subscriptions
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-0818 | 1 Yithemes | 1 Woocommerce Affiliate | 2024-11-21 | 6.1 Medium |
The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin. |
Page 1 of 1.