Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High1
Medium4
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2024-10-04

CVE-2024-8922 - Product Enquiry For Woocommerce Plugin

The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 via deserialization of untrusted input in enquiry_detail.php. This makes it possible for authenticated attackers, with Author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute…

PLUGIN Product Enquiry For Woocommerce

CVE-2024-8922

HIGH CVSS 8.8 2024-09-27
Threat Entry Updated 2025-05-13

CVE-2024-3964 - Product Enquiry For Woocommerce Plugin

The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Product Enquiry For Woocommerce

CVE-2024-3964

MEDIUM CVSS 5.9 2024-07-13
Threat Entry Updated 2025-05-30

CVE-2023-6626 - Product Enquiry For Woocommerce Plugin

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Product Enquiry For Woocommerce

CVE-2023-6626

MEDIUM CVSS 4.8 2024-01-22
Threat Entry Updated 2025-06-20

CVE-2023-6625 - Product Enquiry For Woocommerce Plugin

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Product Enquiry For Woocommerce

CVE-2023-6625

MEDIUM CVSS 4.3 2024-01-22
Threat Entry Updated 2026-02-27

CVE-2023-7151 - Product Enquiry For Woocommerce Plugin

The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Product Enquiry For Woocommerce

CVE-2023-7151

MEDIUM CVSS 6.1 2024-01-16
Scroll to top