All CVEs — page 84 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows remote code execution via the 'first_name' parameter, due to insufficient sanitization and exposure of the site-global proxy verification key.
The flaw allows unauthenticated attackers to disclose other customers' order tokens and manipulate bookings, leading to potential data breaches and unauthorized access.
The Customer Reviews for WooCommerce plugin allows unauthenticated attackers to delete arbitrary attachments from the Media Library by exploiting a lack of proper authorization checks.