Access violation vulnerability in 16 XforWooCommerce Add-On Plugins

Sixteen plugins for WordPress, known as XforWooCommerce Add-On Plugins, have an issue that could allow attackers with subscriber-level permissions or higher to access, edit, or delete WordPress settings, plugin settings, and to see a list of users on the WordPress website. The plugins affected are: Product Filter for WooCommerce, Improved Product Options for WooCommerce, Improved Sale Badges for WooCommerce, Share, Print and PDF Products for WooCommerce, Product Loops for WooCommerce, XforWooCommerce, Package Quantity Discount, Price Commander for WooCommerce, Comment and Review Spam Control for WooCommerce, Add Product Tabs for WooCommerce, Autopilot SEO for WooCommerce, Floating Cart, Live Search for WooCommerce, Bulk Add to Cart for WooCommerce, Live Product Editor for WooCommerce, and Warranties and Returns for WooCommerce. All of these plugins are vulnerable to the authorization bypass issue in various versions listed.

Detected in:

Add Product Tabs for WooCommerce fixed vulnerable versions: >= * < 1.5.0
Bulk Add to Cart for WooCommerce fixed vulnerable versions: >= * < 1.3.0
Comment and Review Spam Control for WooCommerce fixed vulnerable versions: >= * < 1.5.0
Floating Cart for WooCommerce fixed vulnerable versions: >= * < 1.3.0
Improved Product Options for WooCommerce fixed vulnerable versions: >= * < 5.3.0
Improved Sale Badges for WooCommerce fixed vulnerable versions: >= * < 4.4.0
Live Product Editor for WooCommerce fixed vulnerable versions: >= * < 4.7.0
Live Search for WooCommerce fixed vulnerable versions: >= * < 2.1.0
Package Quantity Discount fixed vulnerable versions: >= * < 1.2.0
Price Commander for WooCommerce fixed vulnerable versions: >= * < 1.3.0
Product Filter for WooCommerce fixed vulnerable versions: >= * < 8.2.0
Product Loops for WooCommerce fixed vulnerable versions: >= * < 1.7.0
Share, Print and PDF Products for WooCommerce fixed vulnerable versions: >= * < 2.8.0
Warranties and Returns for WooCommerce fixed vulnerable versions: >= * < 5.3.0
Autopilot SEO for WooCommerce open vulnerable versions: >= * < 1.6.0
XforWooCommerce open vulnerable versions: >= * < 1.7.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.