Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-03-06

CVE-2024-13638 - Order Attachments For Woocommerce Plugin

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain file attachments added to orders.

PLUGIN Order Attachments For Woocommerce

CVE-2024-13638

MEDIUM CVSS 5.9 2025-02-28
Threat Entry Updated 2024-11-25

CVE-2024-9756 - Order Attachments For Woocommerce Plugin

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

PLUGIN Order Attachments For Woocommerce

CVE-2024-9756

MEDIUM CVSS 4.3 2024-10-12
Scroll to top