WPIntell

Source evidence

Nonce verification failed

Extra Product Options for WooCommerce · support · 2024-09-12T08:29:00+00:00

mixedsentiment
highseverity
0.95relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 32 rows with source links

18.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
zeroanarchy resolved
Hi I am getting the following message “Nonce verification failed” in a red box appearing any time I add a product to the cart.. I disabled all plugins to identify the issue and it appears to be caused by this plugin. WordPress Environment<br><br>WordPress address (URL): <br>Site address (URL): <br>WC Version: 9.2.3<br>Legacy REST API Package Version: The Legacy REST API plugin is not installed on this site.<br>Action Scheduler Version: ✔ 3.8.1<br>Log Directory Writable: ✔<br>WP Version: 6.6.2<br>WP Multisite: –<br>WP Memory Limit: 256 MB<br>WP Debug Mode: –<br>WP Cron: ✔<br>Language: en_AU<br>External object cache: – Server Environment<br><br>Server Info: Apache<br>PHP Version: 8.1.29<br>PHP Post Max Size: 512 MB<br>PHP Time Limit: 30<br>PHP Max Input Vars: 1000<br>cURL Version: 7.87.0<br>OpenSSL/1.1.1w<br><br>SUHOSIN Installed: –<br>MySQL Version: 8.0.37<br>Max Upload Size: 2 MB<br>Default Timezone is UTC: ✔<br>fsockopen/cURL: ✔<br>SoapClient: ✔<br>DOMDocument: ✔<br>GZip: ✔<br>Multibyte String: ✔<br>Remote Post: ✔<br>Remote Get: ✔ Database<br><br>WC Database Version: 8.9.0<br>WC Database Prefix: wpsr_<br>Total Database Size: 71.41MB<br>Database Data Size: 48.99MB<br>Database Index Size: 22.42MB<br>wpsr_woocommerce_sessions: Data: 8.10MB + Index: 0.30MB + Engine MyISAM<br>wpsr_woocommerce_api_keys: Data: 0.00MB + Index: 0.01MB + Engine MyISAM<br>wpsr_woocommerce_attribute_taxonomies: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_woocommerce_downloadable_product_permissions: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_woocommerce_order_items: Data: 0.42MB + Index: 0.22MB + Engine MyISAM<br>wpsr_woocommerce_order_itemmeta: Data: 3.09MB + Index: 1.71MB + Engine MyISAM<br>wpsr_woocommerce_tax_rates: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_woocommerce_tax_rate_locations: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_woocommerce_shipping_zones: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_woocommerce_shipping_zone_locations: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_woocommerce_shipping_zone_methods: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_woocommerce_payment_tokens: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_woocommerce_payment_tokenmeta: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_woocommerce_log: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_actionscheduler_actions: Data: 0.17MB + Index: 0.09MB + Engine MyISAM<br>wpsr_actionscheduler_claims: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_actionscheduler_groups: Data: 0.00MB + Index: 0.01MB + Engine MyISAM<br>wpsr_actionscheduler_logs: Data: 0.17MB + Index: 0.13MB + Engine MyISAM<br>wpsr_aio_login_login_attempts: Data: 0.02MB + Index: 0.00MB + Engine InnoDB<br>wpsr_aio_login_login_lockouts: Data: 0.02MB + Index: 0.00MB + Engine InnoDB<br>wpsr_commentmeta: Data: 0.46MB + Index: 0.35MB + Engine MyISAM<br>wpsr_comments: Data: 1.48MB + Index: 0.79MB + Engine MyISAM<br>wpsr_commercekit_searches: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_commercekit_swatches_cache_count: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_commercekit_waitlist: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_commercekit_wishlist: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_commercekit_wishlist_items: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_e_events: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_e_notes: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_e_notes_users_relations: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_e_submissions: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_e_submissions_actions_log: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_e_submissions_values: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_links: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_options: Data: 4.80MB + Index: 0.17MB + Engine MyISAM<br>wpsr_pimwick_gift_card: Data: 0.00MB + Index: 0.01MB + Engine MyISAM<br>wpsr_pimwick_gift_card_activity: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_postmeta: Data: 11.05MB + Index: 5.94MB + Engine MyISAM<br>wpsr_posts: Data: 1.47MB + Index: 0.46MB + Engine MyISAM<br>wpsr_sendlelogs: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_term_relationships: Data: 0.05MB + Index: 0.12MB + Engine MyISAM<br>wpsr_term_taxonomy: Data: 0.00MB + Index: 0.01MB + Engine MyISAM<br>wpsr_termmeta: Data: 0.00MB + Index: 0.01MB + Engine MyISAM<br>wpsr_terms: Data: 0.00MB + Index: 0.01MB + Engine MyISAM<br>wpsr_tm_taskmeta: Data: 0.01MB + Index: 0.01MB + Engine MyISAM<br>wpsr_tm_tasks: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_usermeta: Data: 5.25MB + Index: 4.05MB + Engine MyISAM<br>wpsr_users: Data: 0.42MB + Index: 0.64MB + Engine MyISAM<br>wpsr_wc_admin_note_actions: Data: 0.04MB + Index: 0.01MB + Engine MyISAM<br>wpsr_wc_admin_notes: Data: 0.07MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wc_category_lookup: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wc_customer_lookup: Data: 0.43MB + Index: 0.37MB + Engine MyISAM<br>wpsr_wc_download_log: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wc_order_addresses: Data: 0.02MB + Index: 0.06MB + Engine InnoDB<br>wpsr_wc_order_coupon_lookup: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wc_order_operational_data: Data: 0.02MB + Index: 0.03MB + Engine InnoDB<br>wpsr_wc_order_product_lookup: Data: 0.40MB + Index: 0.31MB + Engine MyISAM<br>wpsr_wc_order_stats: Data: 0.24MB + Index: 0.14MB + Engine MyISAM<br>wpsr_wc_order_tax_lookup: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wc_orders: Data: 0.02MB + Index: 0.11MB + Engine InnoDB<br>wpsr_wc_orders_meta: Data: 0.02MB + Index: 0.03MB + Engine InnoDB<br>wpsr_wc_product_attributes_lookup: Data: 0.02MB + Index: 0.02MB + Engine MyISAM<br>wpsr_wc_product_download_directories: Data: 0.00MB + Index: 0.01MB + Engine MyISAM<br>wpsr_wc_product_meta_lookup: Data: 1.31MB + Index: 1.28MB + Engine MyISAM<br>wpsr_wc_rate_limits: Data: 0.00MB + Index: 0.01MB + Engine MyISAM<br>wpsr_wc_reserved_stock: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wc_tax_rate_classes: Data: 0.00MB + Index: 0.01MB + Engine MyISAM<br>wpsr_wc_webhooks: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wpforms_logs: Data: 0.02MB + Index: 0.00MB + Engine InnoDB<br>wpsr_wpforms_payment_meta: Data: 0.02MB + Index: 0.05MB + Engine InnoDB<br>wpsr_wpforms_payments: Data: 0.02MB + Index: 0.14MB + Engine InnoDB<br>wpsr_wpforms_tasks_meta: Data: 0.09MB + Index: 0.01MB + Engine MyISAM<br>wpsr_wsal_metadata: Data: 3.28MB + Index: 2.82MB + Engine MyISAM<br>wpsr_wsal_occurrences: Data: 5.23MB + Index: 1.59MB + Engine MyISAM<br>wpsr_wt_iew_action_history: Data: 0.10MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wt_iew_cron: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wt_iew_ftp: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_wt_iew_mapping_template: Data: 0.00MB + Index: 0.00MB + Engine MyISAM<br>wpsr_yoast_indexable: Data: 0.50MB + Index: 0.25MB + Engine InnoDB<br>wpsr_yoast_indexable_hierarchy: Data: 0.06MB + Index: 0.05MB + Engine InnoDB<br>wpsr_yoast_migrations: Data: 0.02MB + Index: 0.02MB + Engine InnoDB<br>wpsr_yoast_primary_term: Data: 0.02MB + Index: 0.03MB + Engine InnoDB<br>wpsr_yoast_seo_links: Data: 0.06MB + Index: 0.03MB + Engine InnoDB Post Type Counts<br><br>attachment: 1363<br>custom_css: 2<br>dft_cpo: 6<br>elementor_library: 2<br>nav_menu_item: 33<br>page: 19<br>post: 2<br>product: 569<br>product_variation: 4<br>revision: 26<br>shop_coupon: 1<br>shop_order: 3186<br>size-chart: 12<br>wp_block: 1<br>wp_global_styles: 2<br>wp_navigation: 1<br>wpforms: 2 Security<br><br>Secure connection (HTTPS): ✔<br>Hide errors from visitors: ✔ Active Plugins (21)<br><br>FiboSearch - AJAX Search for WooCommerce: by FiboSearch Team – 1.28.1<br>All In One Login: by AIO Login – 2.0.1<br>CommerceGurus Commercekit: by CommerceGurus – 2.1.0<br>Duplicate Page: by mndpsingh287 – 4.5.4<br>Elementor Pro: by Elementor.com – 3.24.0<br>Elementor: by Elementor.com – 3.24.0<br>Payment Gateway Plugin for PayPal WooCommerce ( Free ): by WebToffee – 1.8.6<br>Extra Product Options for WooCommerce: by actpro – 3.0.8<br>Head, Footer and Post Injections: by Stefano Lissa – 3.2.8<br>Kirki Customizer Framework: by Themeum – 5.1.0<br>PW WooCommerce Gift Cards: by Pimwick<br>LLC – 2.3<br><br>User Role Editor: by Vladimir Garagulya – 4.64.2<br>WooCommerce Weight Based Shipping: by weightbasedshipping.com – 5.9.4<br>Product Size Charts Plugin for WooCommerce: by theDotstore – 2.4.4<br>WooCommerce Stripe Gateway: by WooCommerce – 8.6.1<br>Google Analytics for WooCommerce: by WooCommerce – 2.1.7<br>Woocommerce Products Per Page: by Jeroen Sormani – 1.2.8<br>WooCommerce: by Automattic – 9.2.3<br>Yoast SEO: by Team Yoast – 23.4<br>WP Activity Log: by Melapress – 5.1.0<br>WPForms Lite: by WPForms – 1.9.0.4 Inactive Plugins (1)<br><br>WP-Optimize - Clean, Compress, Cache: by David Anderson<br>Ruhani Rabin<br>Team Updraft – 3.5.0 Dropin Plugins ()<br><br>maintenance.php: maintenance.php Settings<br><br>Legacy API Enabled: –<br>Force SSL: –<br>Currency: AUD ($)<br>Currency Position: left<br>Thousand Separator: ,<br>Decimal Separator: .<br>Number of Decimals: 2<br>Taxonomies: Product Types: external (external)<br>grouped (grouped)<br>pw gift card (pw-gift-card)<br>simple (simple)<br>variable (variable)<br><br>Taxonomies: Product Visibility: exclude-from-catalog (exclude-from-catalog)<br>exclude-from-search (exclude-from-search)<br>featured (featured)<br>outofstock (outofstock)<br>rated-1 (rated-1)<br>rated-2 (rated-2)<br>rated-3 (rated-3)<br>rated-4 (rated-4)<br>rated-5 (rated-5)<br><br>Connected to WooCommerce.com: –<br>Enforce Approved Product Download Directories: ✔<br>HPOS feature enabled: –<br>Order datastore: WC_Order_Data_Store_CPT<br>HPOS data sync enabled: – Logging<br><br>Enabled: ✔<br>Handler: Automattic\WooCommerce\Internal\Admin\Logging\LogHandlerFileV2<br>Retention period: 30 days<br>Level threshold: –<br>Log directory size: 93 KB WC Pages<br><br>Shop base: ❌ Page not set<br>Cart: #7 - /cart/ - Contains the [woocommerce_cart] shortcode<br>Checkout: #8 - /checkout/ - Contains the [woocommerce_checkout] shortcode<br>My account: #9 - /my-account/<br>Terms and conditions: #23768 - /postage-terms/ Theme<br><br>Name: Shoptimizer<br>Version: 2.6.0<br>Author URL: https://www.commercegurus.com/<br>Child Theme: ❌ – If you are modifying WooCommerce on a parent theme that you did not build<br>personally we recommend using a child theme. See: How to create a child theme<br><br>WooCommerce Support: ✔ Templates<br><br>Overrides: – Admin<br><br>Enabled Features: activity-panels<br>analytics<br>product-block-editor<br>coupons<br>core-profiler<br>customize-store<br>customer-effort-score-tracks<br>import-products-task<br>experimental-fashion-sample-products<br>shipping-smart-defaults<br>shipping-setting-tour<br>homescreen<br>marketing<br>mobile-app-banner<br>navigation<br>onboarding<br>onboarding-tasks<br>pattern-toolkit-full-composability<br>product-custom-fields<br>remote-inbox-notifications<br>remote-free-extensions<br>payment-gateway-suggestions<br>printful<br>shipping-label-banner<br>subscriptions<br>store-alerts<br>transient-notices<br>woo-mobile-welcome<br>wc-pay-promotion<br>wc-pay-welcome-page<br>launch-your-store<br><br>Disabled Features: experimental-blocks<br>minified-js<br>product-pre-publish-modal<br>settings<br>async-product-editor-category-field<br>product-editor-template-system<br><br>Daily Cron: ✔ Next scheduled: 2024-09-13 07:16:12 +11:00<br>Options: ✔<br>Notes: 143<br>Onboarding: skipped Action Scheduler<br><br>Complete: 393<br>Oldest: 2024-08-12 16:24:25 +0000<br>Newest: 2024-09-12 08:26:31 +0000<br><br>Failed: 309<br>Oldest: 2022-09-02 03:43:37 +0000<br>Newest: 2024-09-12 08:13:15 +0000<br><br>Pending: 6<br>Oldest: 2024-09-12 18:48:37 +0000<br>Newest: 2024-09-15 13:36:42 +0000 Status report information<br><br>Generated at: 2024-09-12 19:27:23 +11:00<br> The page I need hel...

Comments

2 shown
zeroanarchy 2024-10-26T00:22:00+00:00

The issue appears to be related to a significant security issue identified with this plugin which allows cross site scripting when the plugin is activated. It is recommended that you either address the issue or decommission the plugin. WordPress Extra Product Options for WooCommerce plugin <= 3.0.8 – Cross Site Scripting (XSS) vulnerability. https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/extra-product-options-for-woocommerce/extra-product-options-for-woocommerce-303-authenticated-shop-manager-stored-cross-site-scripting-via-plugin-settings

actpro 2025-02-24T16:09:00+00:00

Hey @zeroanarchy We apologize for the inconvenience caused. The issue has been resolved in the latest version. Please review the changes and let us know if you have any concerns. Thank you for your patience and understanding.