| CVE-2025-58228 | WordPress Quick View for WooCommerce Plugin <= 2.2.16 - Cross Site Scripting (XSS) Vulnerability | ShapedPlugin LLC | Quick View for WooCommerce | Medium | 6.5 | 2025-09-22 18:23:44 | Deep Dive |
| CVE-2025-58247 | WordPress TI WooCommerce Wishlist plugin <= 2.10.0 - Broken Access Control vulnerability | templateinvaders | TI WooCommerce Wishlist | Medium | 5.3 | 2025-09-22 18:23:32 | Deep Dive |
| CVE-2025-58656 | WordPress Estonian Shipping Methods for WooCommerce Plugin <= 1.7.2 - Sensitive Data Exposure Vulnerability | Risto Niinemets | Estonian Shipping Methods for WooCommerce | Medium | 5.3 | 2025-09-22 18:23:06 | Deep Dive |
| CVE-2025-58685 | WordPress Cecabank WooCommerce plugin plugin <= 0.3.4 - Broken Access Control vulnerability | cecabank | Cecabank WooCommerce Plugin | Medium | 5.3 | 2025-09-22 18:22:45 | Deep Dive |
| CVE-2025-58686 | WordPress Perfect Brands for WooCommerce plugin <= 3.6.2 - SQL Injection vulnerability | quadlayers | Perfect Brands for WooCommerce | High | 8.5 | 2025-09-22 18:22:44 | Deep Dive |
| CVE-2025-10142 | PagBank / PagSeguro Connect para WooCommerce <= 4.44.3 - Authenticated (Shop Manager+) SQL Injection | martins56 | PagBank / PagSeguro Connect para WooCommerce | Medium | 4.9 | 2025-09-10 06:38:52 | Deep Dive |
| CVE-2025-9463 | Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net <= 1.117.5 - Authenticated (Contributor+) SQL Injection via order_by Parameter | peachpay | PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) | Medium | 6.5 | 2025-09-10 06:38:46 | Deep Dive |
| CVE-2025-58985 | WordPress Additional Custom Product Tabs for WooCommerce Plugin <= 1.7.3 - Cross Site Scripting (XSS) Vulnerability | WPFactory | Additional Custom Product Tabs for WooCommerce | Medium | 6.5 | 2025-09-09 16:33:13 | Deep Dive |
| CVE-2025-58991 | WordPress WooCommerce Booking Bundle Hours Plugin <= 0.7.4 - Cross Site Request Forgery (CSRF) Vulnerability | Cristiano Zanca | WooCommerce Booking Bundle Hours | High | 7.1 | 2025-09-09 16:33:09 | Deep Dive |
| CVE-2025-47569 | WordPress WooCommerce Ultimate Gift Card plugin <= 2.9.6 - SQL Injection vulnerability | WPSwings | WooCommerce Ultimate Gift Card | Critical | 9.3 | 2025-09-09 16:25:28 | Deep Dive |
| CVE-2025-47570 | WordPress WooCommerce Photo Reviews plugin <= 1.3.13 - Cross Site Scripting (XSS) vulnerability | villatheme | WooCommerce Photo Reviews | High | 7.1 | 2025-09-09 16:25:28 | Deep Dive |
| CVE-2025-10046 | ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction | elextensions | ELEX WooCommerce Google Shopping (Google Product Feed) | Medium | 4.9 | 2025-09-06 06:43:00 | Deep Dive |
| CVE-2025-48317 | WordPress WooCommerce Payment Gateway for Saferpay Plugin <= 0.4.9 - Path Traversal Vulnerability | Stefan Keller | WooCommerce Payment Gateway for Saferpay | High | 7.5 | 2025-09-05 16:15:41 | Deep Dive |
| CVE-2025-58878 | WordPress Woocommerce Gifts Product Plugin <= 1.0.0 - Cross Site Request Forgery (CSRF) Vulnerability | usamafarooq | Woocommerce Gifts Product | Medium | 6.5 | 2025-09-05 13:45:50 | Deep Dive |
| CVE-2025-58856 | WordPress Woocommerce Notify Updated Product Plugin <= 1.6 - Cross Site Request Forgery (CSRF) Vulnerability | ablancodev | Woocommerce Notify Updated Product | Medium | 6.5 | 2025-09-05 13:45:38 | Deep Dive |
| CVE-2025-58804 | WordPress WooCommerce Single Page Checkout Plugin <= 1.2.7 - Cross Site Request Forgery (CSRF) Vulnerability | brijrajs | WooCommerce Single Page Checkout | Medium | 4.3 | 2025-09-05 13:45:09 | Deep Dive |
| CVE-2025-58802 | WordPress TrustMate.io – WooCommerce integration plugin <= 1.16.0 - Cross Site Request Forgery (CSRF) vulnerability | michalzagdan | TrustMate.io – WooCommerce integration | Medium | 4.3 | 2025-09-05 13:45:08 | Deep Dive |
| CVE-2025-58799 | WordPress Custom WooCommerce Checkout Fields Editor Plugin <= 1.3.4 - Cross Site Request Forgery (CSRF) Vulnerability | themelocation | Custom WooCommerce Checkout Fields Editor | Medium | 4.3 | 2025-09-05 13:45:07 | Deep Dive |
| CVE-2025-58788 | WordPress License Manager for WooCommerce Plugin <= 3.0.12 - SQL Injection Vulnerability | Saad Iqbal | License Manager for WooCommerce | High | 7.6 | 2025-09-05 13:44:57 | Deep Dive |
| CVE-2025-58599 | WordPress Order Delivery Date for WooCommerce Plugin <= 4.1.0 - Broken Access Control Vulnerability | tychesoftwares | Order Delivery Date for WooCommerce | Medium | 4.3 | 2025-09-03 14:36:39 | Deep Dive |