Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Product Table for WooCommerce (wooproducttable) | 3.0.2 ~ 3.0.2* | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress WooCommerce plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1020.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-0994 | Hummingbird < 3.3.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1112 | Autolinks <= 1.0.1 - Stored Cross-Site Scripting via CSRF | |
| CVE-2022-1091 | Safe SVG < 1.9.10 - SVG Sanitisation Bypass | |
| CVE-2022-1090 | Good & Bad Comments <= 1.0.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1088 | Page Security & Membership <= 1.5.15 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1063 | Thank Me Later <= 3.3.4 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1054 | RSVP and Event Management < 2.7.8 - Unauthenticated Entries Export | |
| CVE-2022-1037 | EXMAGE < 1.0.7 - Admin+ Blind SSRF | |
| CVE-2022-1001 | WP Downgrade < 1.2.3 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-25120 | Easy Social Feed < 6.2.7 - Reflected Cross-Site Scripting | |
| CVE-2022-0879 | Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting | |
| CVE-2022-0785 | Daily Prayer Time < 2022.03.01 - Unauthenticated SQLi | |
| CVE-2022-0780 | SearchIQ < 3.9 - Unauthenticated Stored XSS | |
| CVE-2022-0765 | Loco Translate < 2.6.1 - Authenticated Stored Cross-Site Scripting | |
| CVE-2022-0737 | Text Hover < 4.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0707 | Easy Digital Downloads < 2.11.6 - Arbitrary Payment Note Insertion via CSRF | |
| CVE-2022-0706 | Easy Digital Downloads < 2.11.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0661 | Ad Injection <= 1.2.0.19 - Admin+ Stored Cross-Site Scripting & RCE |
No comments yet