VendorsYithemesyith_woocommerce_product_add-onsall versions
Vulnerabilities

Yithemes YITH WooCommerce Product Add-Ons

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-49777
WordPress YITH WooCommerce Product Add-Ons Plugin <= 4.3.0 is vulnerable to PHP Object Injection
Published 2023-12-31 · Modified
9.1EPSS 0.007
CVE-2024-50448
WordPress YITH WooCommerce Product Add-Ons plugin <= 4.14.1 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-10-28 · Modified
7.1EPSS 0.003
CVE-2024-35680
WordPress YITH WooCommerce Product Add-Ons plugin <= 4.9.2 - Content Injection vulnerability
Published 2024-06-10 · Modified
5.3EPSS 0.003
CVE-2019-16251
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
Published 2019-10-31 · Modified
4.3EPSS 0.009