Vulnerabilidades en YITHEMES
24 resultadosCVE-2024-4455HIGHYITH WooCommerce Ajax Search <= 2.4.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.0%CVE-2024-0870MEDIUMYITH WooCommerce Gift Cards <= 4.12.0 - Missing Authorization to Unauthenticated WooCommerce Settings UpdateEPSS 0.5%CVE-2026-22333HIGHWordPress YITH WooCommerce Compare plugin <= 3.6.0 - Deserialization of untrusted data vulnerabilityEPSS 0.5%CVE-2024-8665MEDIUMYITH Custom Login <= 1.7.3 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2024-47350CRITICALWordPress YITH WooCommerce Ajax Search plugin <= 2.8.0 - SQL Injection vulnerabilityEPSS 0.4%CVE-2024-27994HIGHWordPress YITH WooCommerce Product Add-Ons plugin <= 4.5.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2023-46635MEDIUMWordPress YITH WooCommerce Product Add-Ons plugin <= 4.2.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-6799MEDIUMYITH Essential Kit for WooCommerce #1 <= 2.34.0 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and DeactivationEPSS 0.3%CVE-2024-35680MEDIUMWordPress YITH WooCommerce Product Add-Ons plugin <= 4.9.2 - Content Injection vulnerabilityEPSS 0.3%CVE-2024-50448HIGHWordPress YITH WooCommerce Product Add-Ons plugin <= 4.14.1 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2024-47367HIGHWordPress YITH WooCommerce Product Add-Ons plugin <= 4.13.0 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2024-35732MEDIUMWordPress YITH Custom Login plugin <= 1.7.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2024-35698MEDIUMWordPress YITH WooCommerce Tab Manager plugin <= 1.35.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2024-37943MEDIUMWordPress YITH WooCommerce Ajax Product Filter plugin <= 5.1.0 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-8617MEDIUMYITH WooCommerce Quick View <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view ShortcodeEPSS 0.3%CVE-2025-12777MEDIUMYITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Wishlist Token Disclosure to Wishlist Item DeletionEPSS 0.3%CVE-2024-34385MEDIUMWordPress YITH WooCommerce Wishlist plugin <= 3.32.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-12427MEDIUMYITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist RenameEPSS 0.2%CVE-2025-5238MEDIUMYITH WooCommerce Wishlist <= 4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via id ParameterEPSS 0.2%CVE-2024-32699MEDIUMWordPress YITH WooCommerce Compare plugin <= 2.37.0 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%