Quantity Plus Minus Button for WooCommerce
Quantity Plus Minus Button for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Quantity Plus Minus Button for WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by Elliot. Quantity Plus Minus Button for WooCommerce is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-48768Quantity Plus Minus Button for WooCommerce by CodeAstrology <= 1.1.9 - Cross-Site Request Forgery via wqpmb_form_submit
Read the full analysisVulnerability Records

Quantity Plus Minus Button for WooCommerce
Author
CodeAstrology IT Firm
woocommerceQuantity Plus/Minus Button for WooCommerce plugin add beautifully designed quantity buttons for WooCommerce quantity input box on the product page which also support for decimal quantity. Easily add plus, minus button for WooCommerce Quantity Input box in everywhere. Such: Single Page, In Loop Quantity input, Cart page etc with custom design. User able to get custom/own color for his plus or minus button. Features 👉 Quantity step supported 👉 Decimal quantity supported 👉 Customizable button design 👉 You can customize button background color and hover 👉 You can customize button text color and hover 👉 You can customize border color and hover 👉 You can customize border width 👉 You can set custom border radius 👉 Live customer support for any Issue. 👉 Well documented 👉 Well commented 👉 Clean code 👉 Compatible with all themes 👉 Compatible with all plugins 👉 Compatible with Woo Product Table 👉 Compatible with the latest version of WordPress 👉 Compatible with the latest version of WooCommerce Demo Link Filter Enable Ajax add to cart for Single Product Page. add_filter('wqpmn_ajax_cart_single_page', '__return_true' ); On off checkbox in admin page using filter add_filter('wqpmb_checkbox_row_validation', '__return_true' ); CSS validation using filter add_filter('wqpmb_css_row_validation', '__return_true' ); Use default WooCommerce template add_filter('wqpmb_show_validation', '__return_true'); Hide on product page add_filter('wqpmb_on_product_page', '__return_false'); Hide on cart page add_filter('wqpmb_on_cart_page', '__return_false'); Hide on Mini Cart page add_filter('wqpmb_on_mini_cart_page', '__return_false'); To Change Templae Base Directory, Use following Hook In that directory, template files folder will be locate add_filter(‘wqpmb_template_base_dir’, $template_base_dir); 👷 HONORABLE CONTRIBUTOR – GitHub 👷 codersaiful (53 commits 1,965 ++ ) unikforceit (1 commit 5 ++ ) fazlebarisn (1 commit 11 ++ ) autocircled (1 commit 110 ++ ) mdibrahimk48 (3 commit 5++) bizzplugin (1 commit 10 ++ ) codeastrology (1 commit 10 ++ ) 👉 You can join here 🥇 CONTRIBUTE 🥇 You are welcome to contribute to this project. Join with us Fork Github repository. If you contribute 1 commit, We will add your name to our plugin’s Contributor table/list of WordPress Plugin too. Privacy Policy Quantity Plus Minus Button for WooCommerce by CodeAstrology uses Appsero SDK to collect some telemetry data upon user’s confirmation. This helps us to troubleshoot problems faster & make product improvements. Appsero SDK does not gather any data by default. The SDK only starts gathering basic telemetry data when a user allows it via the admin notice. We collect the data to ensure a great user experience for all our users. Integrating Appsero SDK DOES NOT IMMEDIATELY start gathering data, without confirmation from users in any case. Learn more about how Appsero collects and uses this data.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C