Xootix Otp Login Woocommerce Gravity Forms vulnerabilities
2 known vulnerabilities affecting xootix/otp_login_woocommerce_gravity_forms.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2024-5324P1HIGHCVSS 8.8ExploitedPoCfixed in 2.6.22024-06-06
CVE-2024-5324 [HIGH] CWE-862 CVE-2024-5324: Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modific
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be u
nvd
CVE-2023-2706P3HIGHCVSS 8.1fixed in 2.32023-05-17
CVE-2023-2706 [HIGH] CWE-287 CVE-2023-2706: The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypas
The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to obtain login codes for administrator
nvd