Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NVillatheme Dropshipping And Fulfillment For Aliexpress And Woocommerce
APPVillatheme≤ 1.1.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2024-8277CRITICAL9.8PL ✓same vendor
Authentication bypass w WooCommerce Photo Reviews Premium dla WordPress
CVE-2022-1037HIGH7.2same vendor
The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which ...
CVE-2024-12861MEDIUM6.5same vendor
The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all vers...
CVE-2024-49288MEDIUM5.9same vendor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaThe...
CVE-2024-1687MEDIUM5.4same vendor
The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unau...