← WordPress Vulnerabilities
WordPress security by component

WooCommerce Box Office

WooCommerce Box Office is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 09, 2024; the highest CVE/CNA score is 6.5.

Plugin slug: woocommerce-box-office

CVE-2023-34003: WooCommerce Box Office: A security weakness

WooCommerce Box Office is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJun 09, 2024
Safe version guidanceSee mitigation notes
Safe version
Jun 09, 2024 CVE-2023-34003
WooCommerce Box Office: A security weakness
WooCommerce Box Office is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD5.3
Mar 26, 2024 CVE-2024-24799
WooCommerce Box Office: A security weakness
WooCommerce Box Office is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD8.8
Aug 30, 2023 CVE-2023-34004
Woocommerce Box Office: Cross-site scripting
Woocommerce Box Office is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4