Login

Plugin Vulnerabilities

A service to protect your site against vulnerabilities in WordPress plugins.

  • Why Plugin Vulnerabilities?
    • We Provide Fixes for Vulnerabilities
    • We Provide Accurate Vulnerability Information
    • Insightful Blocked Exploit Attempt Reporting
    • How We Are Improving the Security of WordPress Plugins
    • Proactive Monitoring for Vulnerabilities in New Versions of WordPress Plugins
    • Select Plugins to Receive Security Reviews
  • Sign Up
    • Set Up
  • PV Firewall
    • Set Up
    • Block Insights
    • WordPress Firewall Comparison
  • Other Services
    • WordPress Security Checkup
    • Plugin Security Review
    • Continuous Plugin Security Review Service
    • Theme Security Review
    • Hacked WordPress Website Cleanup
    • Abandoned WordPress Plugin Maintenance Service
    • Blue Hat Hacking Service for WordPress Plugins/Websites
    • Plugin Vulnerabilities Subscription for ClassicPress
    • Solutions for Web Hosts
    • Solutions for Security Providers
  • Plugin Search
    • WordPress Firewall Tester
    • WordPress Plugins Checker
    • Plugin Security Scorecard
    • Security Scorecard WordPress Plugin
    • WordPress REST API Route Checker
  • Research
    • Plugin Vulnerabilities Survey
    • Report Hacking of WordPress Website
    • Unfixed Security Issues in WordPress
    • Security Advisories on WordPress Plugin Developers
    • WP Security Researcher Database
    • Send us a Tip
  • About
    • WordPress Plugin Zero-Day Vulnerability Exploitation Info Sharing Partnership
    • Get Free Help Fixing A Security Vulnerability In Your WordPress Plugin
    • Contact Us
    • Feedback
    • Report a WordPress Plugin Vulnerability We Are Missing

Tag Archives: Excel Like Price Change for WooCommerce and WP E-commerce

6 Jun 2019

Hackers Appear to be Targeting The WordPress Plugin Excel Like Price Change for WooCommerce and WP E-commerce

As part of making sure the customers of our service are getting the best information on vulnerabilities in WordPress plugins they may be using we monitor for hackers probing for usage of plugins on our website and then try to figure out what the hackers might be looking to exploit. Today we had what looks to be a hacker probing for usage of the plugin Excel Like Price Change for WooCommerce and WP E-commerce (Excel-Like Price Changer for WooCommerce and WP E-commerce) on our website.

As we started looking into what might be causing that we quickly found that the plugin is quite insecure. There are smaller issues like the plugin’s admin pages being limited to users with the “edit_pages” capability instead of “manage_woocommerce”, so Editor level users can access to WooCommerce related data and functionality they are not intended to. What we ran across first though is a much larger issues was that a lot of the plugin’s functionality is accessible those not even logged in to WordPress and that creates various vulnerabilities, we have detailed a couple of obvious ones below that hacker might in the process of exploiting and there look to be more. [Read more]

Plugin Vulnerabilities Posted in Vulnerability Report Arbitrary File Viewing, Excel Like Price Change for WooCommerce and WP E-commerce, Persistent Cross-Site Scripting (XSS), Vulnerability Report Leave a comment

Post navigation

Follow Us

  • Google News
  • Bluesky
  • RSS

Latest Plugin Security Reviews

  • WordPress Plugin Security Review: FV Gravatar Cache
  • WordPress Plugin Security Review: Popup Builder
  • WordPress Plugin Security Review: WP Time Capsule
Powered by WordPress and WooCommerce
© 2016-2025 White Fir Design LLC | Privacy Policy
Fruitful theme by fruitfulcode
↑