📦 Automatewoo

by Woocommerce

🔍 What is Automatewoo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33318

CRITICAL CVSS 9.9 Dec 20, 2023

This vulnerability allows attackers to upload arbitrary files to WordPress sites using vulnerable versions of the AutomateWoo plugin for WooCommerce. Attackers can upload malicious files like PHP shel...

CVE-2023-33330

HIGH CVSS 8.5 Dec 20, 2023

This SQL injection vulnerability in WooCommerce AutomateWoo allows attackers to execute arbitrary SQL commands through the plugin. It affects WordPress sites using AutomateWoo versions up to 4.9.50, p...

CVE-2023-32743

HIGH CVSS 7.6 Dec 20, 2023

This SQL injection vulnerability in the WooCommerce AutomateWoo plugin allows attackers with shop manager privileges to execute arbitrary SQL commands. It affects all versions up to 5.7.1, potentially...

CVE-2023-32745

HIGH CVSS 8.8 Nov 9, 2023

This CSRF vulnerability in the WooCommerce AutomateWoo plugin allows attackers to trick authenticated administrators into performing unintended actions. It affects WordPress sites running AutomateWoo ...

CVE-2023-33319

HIGH CVSS 7.1 May 28, 2023

This vulnerability allows unauthenticated attackers to inject malicious scripts via reflected cross-site scripting (XSS) in the WooCommerce Follow-Up Emails (AutomateWoo) plugin. When exploited, it ca...