| CVE-2025-60171 | WordPress Conditional Cart Messages for WooCommerce – YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) Vulnerability | yourplugins | Conditional Cart Messages for WooCommerce – YourPlugins.com | High | 7.1 | 2025-09-26 08:32:07 | Deep Dive |
| CVE-2025-60159 | WordPress Nota Fiscal Eletrônica WooCommerce plugin <= 3.4.0.9 - Broken Access Control vulnerability | webmaniabr | Nota Fiscal Eletrônica WooCommerce | Medium | 4.3 | 2025-09-26 08:31:58 | Deep Dive |
| CVE-2025-60158 | WordPress Nota Fiscal Eletrônica WooCommerce plugin <= 3.4.0.9 - Cross Site Scripting (XSS) vulnerability | webmaniabr | Nota Fiscal Eletrônica WooCommerce | Medium | 5.9 | 2025-09-26 08:31:58 | Deep Dive |
| CVE-2025-58917 | WordPress Quantities and Units for WooCommerce plugin <= 1.0.13 - Cross Site Scripting (XSS) vulnerability | Nick Verwymeren | Quantities and Units for WooCommerce | Medium | 6.5 | 2025-09-26 08:31:12 | Deep Dive |
| CVE-2025-10173 | ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.3 - Insufficient Authorization to Authenticated (Editor+) Settings Update | roxnor | ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution | Low | 2.7 | 2025-09-26 03:25:34 | Deep Dive |
| CVE-2025-9054 | MultiLoca - WooCommerce Multi Locations Inventory Management <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Options Update via 'wcmlim_settings_ajax_handler' | Techspawn | MultiLoca - WooCommerce Multi Locations Inventory Management | Critical | 9.8 | 2025-09-24 11:18:32 | Deep Dive |
| CVE-2025-10412 | Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9.55 - Unauthenticated Arbitrary File Upload via 'uni_cpo_upload_file' | MooMoo | Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) | Critical | 9.8 | 2025-09-23 09:25:57 | Deep Dive |
| CVE-2025-59559 | WordPress Payrexx Payment Gateway for WooCommerce Plugin <= 3.1.5 - Broken Access Control Vulnerability | payrexx | Payrexx Payment Gateway for WooCommerce | Medium | 4.3 | 2025-09-22 18:26:04 | Deep Dive |
| CVE-2025-59565 | WordPress Upsell Order Bump Offer for WooCommerce Plugin <= 3.0.7 - Cross Site Scripting (XSS) Vulnerability | WP Swings | Upsell Order Bump Offer for WooCommerce | Medium | 6.5 | 2025-09-22 18:26:01 | Deep Dive |
| CVE-2025-53455 | WordPress CashBill.pl – Płatności WooCommerce Plugin <= 3.2.1 - Cross Site Scripting (XSS) Vulnerability | CashBill | CashBill.pl – Płatności WooCommerce | Medium | 5.9 | 2025-09-22 18:25:42 | Deep Dive |
| CVE-2025-57903 | WordPress WooCommerce Additional Fees On Checkout (Free) plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability | WPSuperiors Developer | WooCommerce Additional Fees On Checkout (Free) | Medium | 5.9 | 2025-09-22 18:25:26 | Deep Dive |
| CVE-2025-57904 | WordPress Sales Count Manager for WooCommerce plugin <= 2.6 - Cross Site Scripting (XSS) vulnerability | WP-EXPERTS.IN | Sales Count Manager for WooCommerce | Medium | 5.9 | 2025-09-22 18:25:25 | Deep Dive |
| CVE-2025-57905 | WordPress AgreeMe Checkboxes For WooCommerce Plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) Vulnerability | Amin Y | AgreeMe Checkboxes For WooCommerce | Medium | 4.3 | 2025-09-22 18:25:24 | Deep Dive |
| CVE-2025-57908 | WordPress Product Time Countdown for WooCommerce plugin <= 1.6.5 - Cross Site Scripting (XSS) vulnerability | ProWCPlugins | Product Time Countdown for WooCommerce | Medium | 5.9 | 2025-09-22 18:25:22 | Deep Dive |
| CVE-2025-57914 | WordPress Deliver via Shipos for WooCommerce plugin <= 3.0.2 - Cross Site Request Forgery (CSRF) vulnerability | Matat Technologies | Deliver via Shipos for WooCommerce | Medium | 4.3 | 2025-09-22 18:25:18 | Deep Dive |
| CVE-2025-57917 | WordPress Printcart Web to Print Product Designer for WooCommerce plugin <= 2.4.8 - Broken Access Control vulnerability | printcart | Printcart Web to Print Product Designer for WooCommerce | Medium | 4.3 | 2025-09-22 18:25:16 | Deep Dive |
| CVE-2025-57922 | WordPress Envíos Coordinadora Woocommerce plugin <= 1.1.32 - Sensitive Data Exposure vulnerability | Coordinadora Mercantil S.A. | Envíos Coordinadora Woocommerce | Medium | 5.3 | 2025-09-22 18:25:12 | Deep Dive |
| CVE-2025-57967 | WordPress WPB Quick View for WooCommerce plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability | WPBean | WPB Quick View for WooCommerce | Medium | 6.5 | 2025-09-22 18:24:40 | Deep Dive |
| CVE-2025-57972 | WordPress Helpdesk Support Ticket System for WooCommerce plugin <= 2.1.1 - Broken Access Control vulnerability | WPFactory | Helpdesk Support Ticket System for WooCommerce | Medium | 4.3 | 2025-09-22 18:24:36 | Deep Dive |
| CVE-2025-57977 | WordPress Flexible PDF Invoices for WooCommerce & WordPress Plugin <= 6.0.13 - Cross Site Request Forgery (CSRF) Vulnerability | wpdesk | Flexible PDF Invoices for WooCommerce & WordPress | High | 7.1 | 2025-09-22 18:24:33 | Deep Dive |