{"error":0,"message":null,"data":{"name":"Meta for WooCommerce","plugin":"facebook-for-woocommerce","link":"https:\/\/wordpress.org\/plugins\/facebook-for-woocommerce\/","latest":"1784815140","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"0563492a498fe859c1731f926edfdb92e989fecf4575b2f2b83226668d54bd29","name":"Meta for WooCommerce [facebook-for-woocommerce] < 1.9.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15840","name":"CVE-2019-15840","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15840","description":"[en] The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.","date":"2019-08-30"},{"id":"dbbcccd7-533a-4ab7-af64-c86bf3e2b677","name":"Facebook for WooCommerce &lt;= 1.9.12 - CSRF allowing Option Update","link":"https:\/\/wpscan.com\/vulnerability\/dbbcccd7-533a-4ab7-af64-c86bf3e2b677","description":"The original issue has been fixed via 1.9.14.\r\n\r\nHowever, as additional CSRF checks have been implemented in 1.9.15, the fixed in has been set to 1.9.15","date":null},{"id":"6a5df217d4a5852994fffc8483b8a58d8da384d7","name":"Facebook for WooCommerce <= 1.9.12 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/facebook-for-woocommerce\/facebook-for-woocommerce-1912-cross-site-request-forgery","description":"The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.","date":"2019-06-18"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"becd1b63229bb89c88e61b57970d12c98ff4270dff86bdb246e9db1c714aa907","name":"Meta for WooCommerce [facebook-for-woocommerce] < 1.9.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15841","name":"CVE-2019-15841","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15841","description":"[en] The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.","date":"2019-08-30"},{"id":"3fdd07a89834b3c5a767f93793a7744de3803e04","name":"Facebook for WooCommerce <= 1.9.12 - Cross-Site Request Forgery allowing Option Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/facebook-for-woocommerce\/facebook-for-woocommerce-1912-cross-site-request-forgery-allowing-option-update","description":"The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.","date":"2019-06-18"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"87357544cd31126dafbf781db6823a91d64c7405f4cc6800a3da7389da8100a3","name":"Meta for WooCommerce [facebook-for-woocommerce] < 1.9.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"abf506a08f48a76630ff031f29aa4dbfb05c5567","name":"WordPress Facebook for WooCommerce plugin <= 1.9.12 - Cross-Site Request Forgery (CSRF) vulnerability allowing Option Update","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/facebook-for-woocommerce\/vulnerability\/wordpress-facebook-for-woocommerce-plugin-1-9-12-cross-site-request-forgery-csrf-vulnerability-allowing-option-update","description":"Cross-Site Request Forgery (CSRF) vulnerability allowing Option Update found in WordPress Facebook for WooCommerce plugin (versions <= 1.9.12).","date":"2019-06-25"}],"impact":[]},{"uuid":"846c051227d42782095ad20bf31eed633b62f7f1b414a56f1d151567bea26fb5","name":"Meta for WooCommerce [facebook-for-woocommerce] < 3.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-64296","name":"CVE-2025-64296","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-64296","description":"[en] Missing Authorization vulnerability in Facebook Facebook for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Facebook for WooCommerce: from n\/a through 3.5.7.","date":"2025-10-29"},{"id":"f20f7c4e4d6055380a8f6dadb22a6239c8c524c0","name":"WordPress Facebook for WooCommerce Plugin <= 3.5.7 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/facebook-for-woocommerce\/vulnerability\/wordpress-facebook-for-woocommerce-plugin-3-5-7-broken-access-control-to-notice-dismissal-vulnerability","description":"<p>WordPress Facebook for WooCommerce Plugin <= 3.5.7 is vulnerable to Broken Access Control<\/p><p>Software: Facebook for WooCommerce<\/p><p>Fixed in version 3.5.8 <\/p><p>Affected Version <= 3.5.7<\/p><p>CVE: CVE-2025-64296<\/p>","date":"2025-10-29"},{"id":"16e5bc7283409edd8043cdc836887051214024a0","name":"Facebook for WooCommerce <= 3.5.7 - Missing Authorization to Unauthenticated Notification Dismissal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/facebook-for-woocommerce\/facebook-for-woocommerce-357-missing-authorization-to-unauthenticated-notification-dismissal","description":"The Facebook for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in versions up to, and including, 3.5.7. This makes it possible for unauthenticated attackers to dismiss notices.","date":"2025-10-29"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"00f5285c2ce011613e071079299cd433bfc331c4542e0405f85fdf98b95d1f84","name":"Meta for WooCommerce [facebook-for-woocommerce] < 3.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-49059","name":"CVE-2026-49059","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-49059","description":"[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing.\n\nThis issue affects Facebook for WooCommerce: from n\/a through 3.7.0.","date":"2026-05-27"},{"id":"422ff5dc7a5a31b6a7af515bc7814ecaf146e890","name":"Meta for WooCommerce <= 3.7.0 - Unauthenticated Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/facebook-for-woocommerce\/meta-for-woocommerce-370-unauthenticated-open-redirect","description":"The Meta for WooCommerce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.7.0. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.","date":"2026-05-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"n","a":"n","score":"4.7","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:N\/A:N","score":"4.7","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"be469514db7758b9b253e2fba42f7a1fa87d65f3a5e69dbc4834d24f90857fbf","name":"Meta for WooCommerce [facebook-for-woocommerce] < 3.7.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-66707","name":"CVE-2026-66707","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66707","description":"[en] Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.","date":"2026-08-06"},{"id":"e155cc0c66deb34f09e0bc9682d1ec8d1911f6de","name":"Meta for WooCommerce <= 3.7.5 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/3b0e83af-5abd-4b6e-b606-850c03b05036","description":"The Meta for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-31"},{"id":"6751d313c223f681f4d17df92b9e2de1557da1da","name":"Meta for WooCommerce <= 3.7.5 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/facebook-for-woocommerce\/meta-for-woocommerce-375-unauthenticated-stored-cross-site-scripting","description":"The Meta for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-05-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1785910670"}