| CVE-2025-60192 | WordPress Premmerce Wholesale Pricing for WooCommerce plugin <= 1.1.10 - Local File Inclusion vulnerability | Premmerce | Premmerce Wholesale Pricing for WooCommerce | High | 7.5 | 2025-11-06 15:54:49 | Deep Dive |
| CVE-2025-60191 | WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.10 - Local File Inclusion vulnerability | Premmerce | Premmerce Wishlist for WooCommerce | High | 7.5 | 2025-11-06 15:54:49 | Deep Dive |
| CVE-2025-60189 | WordPress PoloPag – Pix Automático para Woocommerce plugin <= 2.0.9 - Local File Inclusion vulnerability | PoloPag | PoloPag – Pix Automático para Woocommerce | 中危 | - | 2025-11-06 15:54:48 | Deep Dive |
| CVE-2025-47588 | WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.9 - Arbitrary Code Execution vulnerability | acowebs | Dynamic Pricing With Discount Rules for WooCommerce | Critical | 9.1 | 2025-11-06 15:53:36 | Deep Dive |
| CVE-2025-12469 | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending | amans2k | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Medium | 4.3 | 2025-11-05 09:27:40 | Deep Dive |
| CVE-2025-12468 | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure | amans2k | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Medium | 5.3 | 2025-11-05 09:27:39 | Deep Dive |
| CVE-2025-12493 | ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template' | devitemsllc | ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin | Critical | 9.8 | 2025-11-04 11:19:27 | Deep Dive |
| CVE-2025-12389 | Import Export For WooCommerce <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update | sidngr | Import Export For WooCommerce | Medium | 4.3 | 2025-11-04 04:27:21 | Deep Dive |
| CVE-2025-11890 | Crypto Payment Gateway with Payeer for WooCommerce <= 1.0.3 - Unauthenticated Payment Bypass | beycanpress | Crypto Payment Gateway with Payeer for WooCommerce | High | 7.5 | 2025-11-04 04:27:17 | Deep Dive |
| CVE-2025-64358 | WordPress Smart Coupons for WooCommerce plugin <= 2.2.3 - Broken Access Control vulnerability | WebToffee | Smart Coupons for WooCommerce | Medium | 4.3 | 2025-10-31 11:42:28 | Deep Dive |
| CVE-2025-12115 | WPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price Alteration | wpclever | WPC Name Your Price for WooCommerce | High | 7.5 | 2025-10-31 09:27:22 | Deep Dive |
| CVE-2025-10897 | WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read | JMA Plugins | WooCommerce Designer Pro | High | 8.6 | 2025-10-31 07:26:40 | Deep Dive |
| CVE-2025-64290 | WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerability | Premmerce | Premmerce Product Search for WooCommerce | Medium | 4.3 | 2025-10-29 08:38:15 | Deep Dive |
| CVE-2025-64289 | WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.5 - Cross Site Scripting (XSS) vulnerability | Premmerce | Premmerce Product Search for WooCommerce | - | - | 2025-10-29 08:38:15 | Deep Dive |
| CVE-2025-64285 | WordPress Premmerce Wholesale Pricing for WooCommerce plugin <= 1.1.10 - Broken Access Control vulnerability | Premmerce | Premmerce Wholesale Pricing for WooCommerce | Medium | 5.4 | 2025-10-29 08:38:13 | Deep Dive |
| CVE-2025-64200 | WordPress Email Template Customizer for WooCommerce plugin <= 1.2.17 - Cross Site Scripting (XSS) vulnerability | VillaTheme | Email Template Customizer for WooCommerce | - | - | 2025-10-29 08:38:06 | Deep Dive |
| CVE-2023-7320 | WooCommerce <= 7.8.2 - Sensitive Information Exposure | automattic | WooCommerce | Medium | 5.3 | 2025-10-29 06:45:49 | Deep Dive |
| CVE-2025-49042 | WordPress WooCommerce plugin <= 10.0.2 - Cross Site Scripting (XSS) vulnerability | Automattic | WooCommerce | Medium | 5.9 | 2025-10-29 04:50:13 | Deep Dive |
| CVE-2025-64296 | WordPress Facebook for WooCommerce plugin <= 3.5.7 - Broken Access Control to Notice Dismissal vulnerability | Facebook | Facebook for WooCommerce | Medium | 5.3 | 2025-10-29 04:08:46 | Deep Dive |
| CVE-2025-11735 | HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.1 - Unauthenticated SQL Injection via `phrase` Parameter | realmag777 | HUSKY – Products Filter Professional for WooCommerce | High | 7.5 | 2025-10-28 05:27:30 | Deep Dive |