| CVE-2025-64380 | WordPress Booster for WooCommerce plugin <= 7.3.2 - Cross Site Scripting (XSS) vulnerability | Pluggabl | Booster for WooCommerce | 中危 | - | 2025-11-13 09:24:35 | Deep Dive |
| CVE-2025-64382 | WordPress Order Export & Order Import for WooCommerce plugin <= 2.6.7 - Broken Access Control vulnerability | WebToffee | Order Export & Order Import for WooCommerce | 中危 | - | 2025-11-13 09:24:35 | Deep Dive |
| CVE-2025-64379 | WordPress Booster for WooCommerce plugin <= 7.4.0 - Broken Access Control vulnerability | Pluggabl | Booster for WooCommerce | 中危 | - | 2025-11-13 09:24:34 | Deep Dive |
| CVE-2025-64269 | WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.150 - Broken Access Control vulnerability | EDGARROJAS | WooCommerce PDF Invoice Builder | Medium | 4.3 | 2025-11-13 09:24:30 | Deep Dive |
| CVE-2025-64267 | WordPress WooCommerce Ultimate Points And Rewards plugin <= 2.10.2 - Sensitive Data Exposure vulnerability | WPSwings | WooCommerce Ultimate Points And Rewards | Medium | 4.3 | 2025-11-13 09:24:30 | Deep Dive |
| CVE-2025-12903 | Payment Plugins Braintree For WooCommerce <= 3.2.78 - Missing Authorization to Payment Token Exposure and Transaction Fraud | paymentplugins | Payment Plugins Braintree For WooCommerce | High | 7.5 | 2025-11-12 08:28:05 | Deep Dive |
| CVE-2025-12087 | Wishlist and Save for later for Woocommerce <= 1.1.22 - Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion | acowebs | Wishlist and Save for later for Woocommerce | Medium | 4.3 | 2025-11-12 04:29:09 | Deep Dive |
| CVE-2025-11237 | Make Email Customizer for WooCommerce <= 1.0.6 - Subscriber+ Arbitrary Options Update | Unknown | Make Email Customizer for WooCommerce | 中危 | - | 2025-11-11 06:00:04 | Deep Dive |
| CVE-2025-11821 | Woocommerce – Products By Custom Tax <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | elvismdev | Woocommerce – Products By Custom Tax | Medium | 6.4 | 2025-11-11 03:30:49 | Deep Dive |
| CVE-2025-12588 | USB Qr Code Scanner For Woocommerce <= 1.0.0 - Cross-Site Request Forgery to Settings Update | behzadrohizadeh | USB Qr Code Scanner For Woocommerce | Medium | 4.3 | 2025-11-11 03:30:42 | Deep Dive |
| CVE-2025-11967 | Mail Mint <= 1.18.10 - Authenticated (Admin+) Arbitrary File Upload | getwpfunnels | Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails | High | 7.2 | 2025-11-08 09:28:12 | Deep Dive |
| CVE-2025-12621 | Flexible Refund and Return Order for WooCommerce <= 1.0.42 - Incorrect Authorization to Authenticated (Contributor+) Refund Status Update | wpdesk | Flexible Refund and Return Order for WooCommerce | Medium | 5.3 | 2025-11-08 07:26:28 | Deep Dive |
| CVE-2025-64196 | WordPress Booster for WooCommerce plugin <= 7.2.5 - Cross Site Scripting (XSS) vulnerability | Pluggabl | Booster for WooCommerce | 中危 | - | 2025-11-06 15:56:07 | Deep Dive |
| CVE-2025-60247 | WordPress Bux Woocommerce plugin <= 1.2.3 - Broken Access Control vulnerability | Bux | Bux Woocommerce | Medium | 6.5 | 2025-11-06 15:55:21 | Deep Dive |
| CVE-2025-60248 | WordPress WPC Product Options for WooCommerce plugin <= 3.1.3 - Local File Inclusion vulnerability | WPClever | WPC Product Options for WooCommerce | 中危 | - | 2025-11-06 15:55:21 | Deep Dive |
| CVE-2025-60243 | WordPress Selling Commander for WooCommerce plugin <= 1.2.46 - Privilege Escalation vulnerability | Holest Engineering | Selling Commander for WooCommerce | 中危 | - | 2025-11-06 15:55:16 | Deep Dive |
| CVE-2025-60235 | WordPress Support Ticket System for WooCommerce plugin <= 2.0.7 - Arbitrary File Upload vulnerability | Plugify | Support Ticket System for WooCommerce (Premium) | 中危 | - | 2025-11-06 15:55:08 | Deep Dive |
| CVE-2025-60207 | WordPress Custom User Registration Fields for WooCommerce plugin <= 2.1.2 - Arbitrary File Upload Vulnerability | Addify | Custom User Registration Fields for WooCommerce | 中危 | - | 2025-11-06 15:55:06 | Deep Dive |
| CVE-2025-60204 | WordPress WooCommerce Store Toolkit plugin <= 2.4.3 - Local File Inclusion vulnerability | Josh Kohlbach | WooCommerce Store Toolkit | High | 7.5 | 2025-11-06 15:55:05 | Deep Dive |
| CVE-2025-60194 | WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Local File Inclusion vulnerability | Premmerce | Premmerce Product Search for WooCommerce | High | 7.5 | 2025-11-06 15:54:51 | Deep Dive |