WordPress 插件 Storegrowth Sales Booster 在 2.1.0 及更早版本中存在授权缺失漏洞。该漏洞是由于在 AJAX 处理函数 bogo_category_msg_create() 中缺少权限检查所致。该 AJAX 处理程序同时注册给了已认证用户(wp_ajax_)和未认证用户(wp_ajax_nopriv_),并且仅验证一个通过 front_scripts() 函数在每个前端页面通过 wp_localize_script() 公开发布的非ces(nonce)值('ajd_prote
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wedevs | StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce | ≤ 2.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wedevs | StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce | 0 ~ 2.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13440 | 7.2 HIGH | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick V |
| CVE-2026-15411 | 5.3 MEDIUM | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick V |
No comments yet