| CVE-2025-68029 | WordPress Wallet System for WooCommerce plugin <= 2.7.3 - Sensitive Data Exposure vulnerability | WP Swings | Wallet System for WooCommerce | 中危 | - | 2026-01-05 10:37:19 | Deep Dive |
| CVE-2025-62088 | WordPress WordPress & WooCommerce Scraper plugin, Import Data from Any Site plugin <= 1.0.7 - Server Side Request Forgery (SSRF) vulnerability | extendons | WordPress & WooCommerce Scraper Plugin, Import Data from Any Site | Medium | 5.4 | 2025-12-31 17:04:44 | Deep Dive |
| CVE-2025-49352 | WordPress Order Cancellation & Returns for WooCommerce plugin <= 1.1.10 - Insecure Direct Object References (IDOR) vulnerability | YoOhw Studio | Order Cancellation & Returns for WooCommerce | Medium | 4.3 | 2025-12-31 16:25:45 | Deep Dive |
| CVE-2025-49356 | WordPress Orders Chat for WooCommerce plugin <= 1.2.0 - Broken Access Control vulnerability | Mykola Lukin | Orders Chat for WooCommerce | Medium | 4.3 | 2025-12-31 16:07:40 | Deep Dive |
| CVE-2025-62080 | WordPress Live Shopping & Shoppable Videos For WooCommerce plugin <= 2.2.0 - Cross Site Request Forgery (CSRF) vulnerability | Channelize.io Team | Live Shopping & Shoppable Videos For WooCommerce | Medium | 4.3 | 2025-12-31 15:44:46 | Deep Dive |
| CVE-2025-62081 | WordPress Live Shopping & Shoppable Videos For WooCommerce plugin <= 2.2.0 - Broken Access Control vulnerability | Channelize.io Team | Live Shopping & Shoppable Videos For WooCommerce | Medium | 5.3 | 2025-12-31 15:00:19 | Deep Dive |
| CVE-2025-62091 | WordPress Serial Codes Generator and Validator with WooCommerce Support plugin <= 2.8.2 - Broken Access Control vulnerability | Vollstart | Serial Codes Generator and Validator with WooCommerce Support | Medium | 5.4 | 2025-12-31 14:19:32 | Deep Dive |
| CVE-2025-62750 | WordPress WooCommerce Parcelas plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability | Filipe Seabra | WooCommerce Parcelas | Medium | 5.9 | 2025-12-31 13:32:34 | Deep Dive |
| CVE-2025-62096 | WordPress Maximum Products per User for WooCommerce plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability | WPFactory | Maximum Products per User for WooCommerce | Medium | 6.5 | 2025-12-31 13:12:18 | Deep Dive |
| CVE-2025-62748 | WordPress Web and WooCommerce Addons for WPBakery Builder plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability | Genetech Products | Web and WooCommerce Addons for WPBakery Builder | Medium | 6.5 | 2025-12-31 12:02:49 | Deep Dive |
| CVE-2025-14509 | Lucky Wheel for WooCommerce – Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags | villatheme | Lucky Wheel for WooCommerce – Spin a Sale | High | 7.2 | 2025-12-30 11:14:25 | Deep Dive |
| CVE-2025-69088 | WordPress Combo Offers WooCommerce plugin <= 4.2 - Cross Site Scripting (XSS) vulnerability | Vidish | Combo Offers WooCommerce | 中危 | - | 2025-12-30 10:47:58 | Deep Dive |
| CVE-2025-69027 | WordPress Product Delivery Date for WooCommerce – Lite plugin <= 3.2.0 - Broken Access Control vulnerability | tychesoftwares | Product Delivery Date for WooCommerce – Lite | Medium | 5.3 | 2025-12-30 10:47:56 | Deep Dive |
| CVE-2025-68994 | WordPress Product Loops for WooCommerce plugin <= 2.1.2 - Broken Access Control vulnerability | XforWooCommerce | Product Loops for WooCommerce | Medium | 5.3 | 2025-12-30 10:47:51 | Deep Dive |
| CVE-2025-68993 | WordPress Share, Print and PDF Products for WooCommerce plugin <= 3.1.2 - Broken Access Control vulnerability | XforWooCommerce | Share, Print and PDF Products for WooCommerce | Medium | 5.3 | 2025-12-30 10:47:51 | Deep Dive |
| CVE-2025-67909 | WordPress Membership For WooCommerce plugin <= 3.0.3 - Insecure Direct Object References (IDOR) vulnerability | WP Swings | Membership For WooCommerce | High | 7.5 | 2025-12-24 13:10:25 | Deep Dive |
| CVE-2025-68528 | WordPress Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability | WPFactory | Free Shipping Bar: Amount Left for Free Shipping for WooCommerce | Medium | 6.5 | 2025-12-24 12:31:26 | Deep Dive |
| CVE-2025-68519 | WordPress Brands for WooCommerce plugin <= 3.8.6.3 - SQL Injection vulnerability | BeRocket | Brands for WooCommerce | High | 8.5 | 2025-12-24 12:31:23 | Deep Dive |
| CVE-2025-13773 | Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Unauthenticated Remote Code Execution | tychesoftwares | Print Invoice & Delivery Notes for WooCommerce | Critical | 9.8 | 2025-12-24 04:32:56 | Deep Dive |
| CVE-2023-52210 | WordPress Product Delivery Date for WooCommerce – Lite plugin <= 2.7.0 - Broken Access Control vulnerability | Tyche softwares | Product Delivery Date for WooCommerce – Lite | Medium | 5.3 | 2025-12-23 12:02:46 | Deep Dive |