| CVE-2025-12655 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Missing Authorization to Unauthenticated Limited File Write | hippooo | Hippoo Mobile App for WooCommerce | Medium | 5.3 | 2025-12-12 06:32:59 | Deep Dive |
| CVE-2025-13314 | Product Filtering by Categories, Tags, Price Range for WooCommerce <= 1.1.6 - Missing Authorization to Unauthenticated Plugin Settings Modification | markutos987 | Filter Plus – Product Filter & WordPress Filter | Medium | 5.3 | 2025-12-12 03:20:57 | Deep Dive |
| CVE-2025-13440 | Premmerce Wishlist for WooCommerce <= 1.1.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wishlist Deletion | premmerce | Premmerce Wishlist for WooCommerce | Medium | 5.3 | 2025-12-12 03:20:51 | Deep Dive |
| CVE-2025-14165 | Kirim.Email WooCommerce Integration <= 1.2.9 - Cross-Site Request Forgery to Settings Update | developerke | Kirim.Email WooCommerce Integration | Medium | 4.3 | 2025-12-12 03:20:48 | Deep Dive |
| CVE-2025-12783 | Premmerce Brands for WooCommerce <= 1.2.13 - Missing Authorization To Authenticated (Subscriber+) Brand Permalink Settings Update | premmerce | Premmerce Brands for WooCommerce | Medium | 4.3 | 2025-12-12 03:20:47 | Deep Dive |
| CVE-2025-12883 | Campay Woocommerce Payment Gateway <= 1.2.2 - Unauthenticated Payment Bypass | campay | Campay Woocommerce Payment Gateway | Medium | 5.3 | 2025-12-12 03:20:43 | Deep Dive |
| CVE-2025-13339 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read | hippooo | Hippoo Mobile App for WooCommerce | High | 7.5 | 2025-12-10 04:24:13 | Deep Dive |
| CVE-2025-13924 | Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.17 - Cross-Site Request Forgery to Product Field Group Duplication and Publication | maartenbelmans | Advanced Product Fields (Product Addons) for WooCommerce | Medium | 4.3 | 2025-12-09 17:23:32 | Deep Dive |
| CVE-2025-63024 | WordPress Order Delivery Date for WooCommerce plugin <= 4.3.1 - Broken Access Control vulnerability | tychesoftwares | Order Delivery Date for WooCommerce | Medium | 5.4 | 2025-12-09 14:52:29 | Deep Dive |
| CVE-2025-63015 | WordPress WooCommerce Payment Gateway – Paysera plugin <= 3.10.0 - Broken Access Control vulnerability | paysera | WooCommerce Payment Gateway - Paysera | Medium | 4.3 | 2025-12-09 14:52:28 | Deep Dive |
| CVE-2025-63023 | WordPress Payment Gateway for PayPal on WooCommerce plugin <= 9.0.53 - Broken Access Control vulnerability | Easy Payment | Payment Gateway for PayPal on WooCommerce | Medium | 5.3 | 2025-12-09 14:52:28 | Deep Dive |
| CVE-2025-62995 | WordPress MultiParcels Shipping For WooCommerce plugin <= 1.30.12 - Broken Access Control vulnerability | multiparcels | MultiParcels Shipping For WooCommerce | - | - | 2025-12-09 14:52:26 | Deep Dive |
| CVE-2025-62870 | WordPress Eupago Gateway For Woocommerce plugin <= 4.7.1 - Broken Access Control vulnerability | Eupago | Eupago Gateway For Woocommerce | - | - | 2025-12-09 14:52:24 | Deep Dive |
| CVE-2025-62151 | WordPress Virtuaria PagBank / PagSeguro para Woocommerce plugin <= 3.6.3 - Broken Access Control vulnerability | Virtuaria | Virtuaria PagBank / PagSeguro para Woocommerce | Medium | 5.3 | 2025-12-09 14:52:21 | Deep Dive |
| CVE-2025-67589 | WordPress WooCommerce PDF Invoices & Packing Slips plugin <= 4.9.1 - Broken Access Control vulnerability | WP Overnight | WooCommerce PDF Invoices & Packing Slips | Medium | 4.3 | 2025-12-09 14:14:17 | Deep Dive |
| CVE-2025-67580 | WordPress Constant Contact + WooCommerce plugin <= 2.4.1 - Broken Access Control vulnerability | Constant Contact | Constant Contact + WooCommerce | Medium | 5.3 | 2025-12-09 14:14:15 | Deep Dive |
| CVE-2025-67564 | WordPress Pixel Manager for WooCommerce plugin <= 1.51.1 - Sensitive Data Exposure vulnerability | alekv | Pixel Manager for WooCommerce | - | - | 2025-12-09 14:14:11 | Deep Dive |
| CVE-2025-67542 | WordPress Multi-Step Checkout for WooCommerce plugin <= 2.33 - Cross Site Scripting (XSS) vulnerability | SilkyPress | Multi-Step Checkout for WooCommerce | - | - | 2025-12-09 14:14:05 | Deep Dive |
| CVE-2025-66528 | WordPress Thank You Page Customizer for WooCommerce plugin <= 1.1.8 - Broken Access Control vulnerability | VillaTheme | Thank You Page Customizer for WooCommerce | Medium | 4.3 | 2025-12-09 14:13:53 | Deep Dive |
| CVE-2025-12091 | Search, Filters & Merchandising for WooCommerce <= 3.0.67 - Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation | instantsearchplus | Search, Filters & Merchandising for WooCommerce | Medium | 4.3 | 2025-12-06 05:49:35 | Deep Dive |