The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This critical vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to elevate their privileges to Administrator by creating an account during checkout with a modified JSON body specifying administrator (or any other role slug) as the d [truncated]
A Path Traversal vulnerability was discovered in Addify Tax Exempt for WooCommerce, affecting versions from n/a before 1.9.5. This issue allows attackers to traverse paths on the server, potentially accessing sensitive files. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of Addify Tax Exempt for WooCommerce, especially those using versions prior to 1.9.5, should be aware of thi [truncated]