CedcommerceCVEs & Vulnerabilities

8 CVEs affecting Cedcommerce products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wholesale market for woocommerce 4wholesale market 2one click order re-order 1recently viewed and most viewed products 1smsa shipping for woocommerce 1
CVE-2022-4363MEDIUM

The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack

17 May 2025
6.5
CVSS
CVE-2024-5641MEDIUM

The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the plugin settings, including adding stored cross-site scripting.

4 Jul 2024
5.4
CVSS
CVE-2023-47646MEDIUM

Auth. (Shop Manager+) Stored Cross-Site Scripting (XSS) vulnerability in CedCommerce Recently viewed and most viewed products plugin <= 1.1.1 versions.

14 Nov 2023
4.8
CVSS
CVE-2022-4298CRITICAL

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

3 Jan 2023
9.8
CVSS
CVE-2022-4109LOW

The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)

3 Jan 2023
2.7
CVSS
CVE-2022-4108MEDIUM

The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system path, allowing high privilege users such as admin to download arbitrary file from the server even when they should not be able to (for example in multisite)

19 Dec 2022
4.9
CVSS
CVE-2022-4107MEDIUM

The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

19 Dec 2022
6.5
CVSS
CVE-2022-4106HIGH

The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

19 Dec 2022
7.5
CVSS
← PrevPage 1 / 1Next →