| CVE-2021-25001 | Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in Product XML Feeds Module | Unknown | Booster for WooCommerce | 中危 | - | 2022-01-03 12:49:12 | Deep Dive |
| CVE-2021-25000 | Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in General Module | Unknown | Booster for WooCommerce | 中危 | - | 2022-01-03 12:49:11 | Deep Dive |
| CVE-2021-24991 | WooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site Scripting | Unknown | WooCommerce PDF Invoices & Packing Slips | 中危 | - | 2022-01-03 12:49:10 | Deep Dive |
| CVE-2021-24999 | Booster for Woocommerce < 5.4.9 - Reflected Cross-Site Scripting in PDF Invoicing Module | Unknown | Booster for WooCommerce | 中危 | - | 2022-01-03 12:49:10 | Deep Dive |
| CVE-2021-24849 | WCFM - WooCommerce Multivendor Marketplace < 3.4.12 - Unauthenticated SQL Injection | Unknown | WCFM Marketplace – Best Multivendor Marketplace for WooCommerce | 超危 | - | 2021-12-21 08:45:32 | Deep Dive |
| CVE-2021-24846 | Ni WooCommerce Custom Order Status < 1.9.7 - Subscriber+ SQL Injection | Unknown | Ni WooCommerce Custom Order Status | 高危 | - | 2021-12-21 08:45:31 | Deep Dive |
| CVE-2021-39308 | WooCommerce myghpay Payment Gateway <= 3.0 Reflected Cross-Site Scripting | WooCommerce myghpay Payment Gateway | WooCommerce myghpay Payment Gateway | Medium | 6.1 | 2021-12-14 15:50:16 | Deep Dive |
| CVE-2021-39309 | Parsian Bank Gateway for Woocommerce <= 1.0 Reflected Cross-Site Scripting | Parsian Bank Gateway for Woocommerce | Parsian Bank Gateway for Woocommerce | Medium | 6.1 | 2021-12-14 15:50:13 | Deep Dive |
| CVE-2021-39314 | WooCommerce EnvioPack <= 1.2 Reflected Cross-Site Scripting | WooCommerce EnvioPack | WooCommerce EnvioPack | Medium | 6.1 | 2021-12-14 15:50:12 | Deep Dive |
| CVE-2021-42367 | Variation Swatches for WooCommerce <= 2.1.1 Authenticated Stored Cross-Site Scripting | Variation Swatches for WooCommerce | Variation Swatches for WooCommerce | Medium | 6.4 | 2021-12-14 15:50:10 | Deep Dive |
| CVE-2021-24938 | WooCommerce Currency Switcher < 1.3.7.1 - Reflected Cross-Site Scripting | Unknown | WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency | 中危 | - | 2021-12-06 15:55:37 | Deep Dive |
| CVE-2021-42363 | Preview E-Mails for WooCommerce <= 1.6.8 Reflected Cross-Site Scripting | Preview E-Mails for WooCommerce | Preview E-Mails for WooCommerce | Medium | 6.1 | 2021-11-19 15:35:09 | Deep Dive |
| CVE-2021-24835 | WCFM - Frontend Manager for WooCommerce < 6.5.12 - Customer/Subscriber+ SQL Injection | Unknown | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | 高危 | - | 2021-11-08 17:35:31 | Deep Dive |
| CVE-2021-39347 | Stripe for WooCommerce 3.0.0 - 3.3.9 Missing Authorization Controls to Financial Account Hijacking | Stripe for WooCommerce | Stripe for WooCommerce | Medium | 4.3 | 2021-10-04 17:21:49 | Deep Dive |
| CVE-2021-24679 | Bitcoin / AltCoin Payment Gateway for WooCommerce < 1.6.1 - Reflected Cross-Site Scripting | Unknown | Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop | 中危 | - | 2021-10-04 11:20:23 | Deep Dive |
| CVE-2021-34636 | Countdown and CountUp, WooCommerce Sales Timer <= 1.5.7 Cross-Site Request Forgery to Stored Cross-Site Scripting | WpDevArt | Countdown and CountUp, WooCommerce Sales Timers | High | 8.8 | 2021-09-28 13:53:30 | Deep Dive |
| CVE-2021-24511 | Create WooCommerce Product Feeds For 40+ Merchants < 3.3.1.0 - Authenticated SQL Injection | Unknown | Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and More | 高危 | - | 2021-09-20 10:06:13 | Deep Dive |
| CVE-2021-38341 | WooCommerce Payment Gateway Per Category <= 2.0.10 Reflected Cross-Site Scripting | WooCommerce Payment Gateway Per Category | WooCommerce Payment Gateway Per Category | Medium | 6.1 | 2021-09-10 13:33:07 | Deep Dive |
| CVE-2021-38349 | Integration of Moneybird for WooCommerce <= 2.1.1 Reflected Cross-Site Scripting | Integration of Moneybird for WooCommerce | Integration of Moneybird for WooCommerce | Medium | 6.1 | 2021-09-10 13:32:55 | Deep Dive |
| CVE-2021-24588 | SMS Alert Order Notifications – WooCommerce < 3.4.7 Authenticated Cross Site Scripting | Unknown | SMS Alert Order Notifications – WooCommerce | 中危 | - | 2021-09-06 11:09:28 | Deep Dive |