The Lab · 2026-03-31 06:57:06 · GitHub Issues
A critical security vulnerability has been identified in the PPOM for WooCommerce plugin, exposing sensitive store data to unauthenticated users. The plugin's entire REST API, comprising seven distinct endpoints, is configured with a blanket `'permission_callback' => '__return_true'`. This configuration effectively byp...
The Lab · 2026-04-15 13:23:00 · GitHub Issues
A critical, unauthenticated Local File Inclusion (LFI) vulnerability has been publicly documented for the HUSKY Products Filter Professional plugin for WooCommerce, designated as CVE-2025-1661. The flaw allows attackers to directly target WordPress sites by sending a malicious POST request to the `/wp-admin/admin-ajax....
The Lab · 2026-05-14 13:18:26 · Mastodon:mastodon.social:#infosec
A critical missing authorization vulnerability has been identified in InfusedWoo Pro, a WordPress plugin widely used for integrating WooCommerce with the Infusionsoft CRM platform. Tracked as CVE-2026-6512 and classified under CWE-862 (Missing Authorization), the flaw affects all versions up to and including 5.1.2. The...