| CVE-2024-13320 | CURCY - WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection | villatheme | CURCY - WooCommerce Multi Currency - Currency Switcher | High | 7.5 | 2025-03-07 06:40:04 | Deep Dive |
| CVE-2024-13868 | Easy Broken Link Checker <= 9.0.2 - Reflected XSS | Unknown | URL Shortener | Conversion Tracking | AB Testing | WooCommerce | 中危 | - | 2025-03-06 06:00:04 | Deep Dive |
| CVE-2025-1463 | Spreadsheet Integration <= 3.8.2 - Cross-Site Request Forgery to Arbitrary Post Publish | javmah | WPGSI: Spreadsheet Integration | Medium | 4.3 | 2025-03-05 11:22:08 | Deep Dive |
| CVE-2024-13747 | WooMail - WooCommerce Email Customizer <= 3.0.34 - Authenticated (Subscriber+) Missing Authorization to SQL Injection | CidCode | WooMail - WooCommerce Email Customizer | Medium | 4.3 | 2025-03-05 09:21:50 | Deep Dive |
| CVE-2024-13810 | Zass - WooCommerce Theme for Handmade Artists and Artisans <= 3.9.9.10 - Missing Authorization to Authenticated (Subscriber+) Demo Import | AlThemist | Zass - WooCommerce Theme for Handmade Artists and Artisans | Medium | 4.3 | 2025-03-05 09:21:49 | Deep Dive |
| CVE-2024-13811 | Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme <= 4.5.7 - Missing Authorization to Authenticated (Subscriber+) Demo Import | AlThemist | Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme | Medium | 4.3 | 2025-03-05 09:21:46 | Deep Dive |
| CVE-2025-0956 | WooCommerce Recover Abandoned Cart <= 24.4.0 - Unauthenticated PHP Object Injection | FantasticPlugins | WooCommerce Recover Abandoned Cart | High | 8.1 | 2025-03-05 09:21:44 | Deep Dive |
| CVE-2024-13724 | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization | wpswings | Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments | Medium | 4.3 | 2025-03-04 08:23:42 | Deep Dive |
| CVE-2024-13682 | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery | wpswings | Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments | Medium | 4.3 | 2025-03-04 08:23:41 | Deep Dive |
| CVE-2025-26535 | WordPress Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop plugin <= 1.7.6 - SQL Injection vulnerability | CodeSolz | Bitcoin / AltCoin Payment Gateway for WooCommerce | Critical | 9.3 | 2025-03-03 13:30:28 | Deep Dive |
| CVE-2025-25119 | WordPress Woocommerce osCommerce Sync plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerability | Alejandro Aranda | Woocommerce osCommerce Sync | High | 7.1 | 2025-03-03 13:30:24 | Deep Dive |
| CVE-2025-23903 | WordPress Local Shipping Labels for WooCommerce Plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability | woofx | Local Shipping Labels for WooCommerce | High | 7.1 | 2025-03-03 13:30:21 | Deep Dive |
| CVE-2025-23731 | WordPress Tax Report for WooCommerce plugin <= 2.2 - Reflected Cross Site Scripting (XSS) vulnerability | infosoftplugin | Tax Report for WooCommerce | High | 7.1 | 2025-03-03 13:30:17 | Deep Dive |
| CVE-2025-23668 | WordPress ChatGPT Open AI Images & Content for WooCommerce plugin <= 2.2.0 - Reflected Cross Site Scripting (XSS) vulnerability | Mauricio Urrego | ChatGPT Open AI Images & Content for WooCommerce | High | 7.1 | 2025-03-03 13:30:16 | Deep Dive |
| CVE-2025-23481 | WordPress Ni WooCommerce Sales Report Email plugin <= 3.1.4 - Reflected Cross Site Scripting (XSS) vulnerability | Anzar Ahmed | Ni WooCommerce Sales Report Email | High | 7.1 | 2025-03-03 13:30:06 | Deep Dive |
| CVE-2025-23450 | WordPress AW WooCommerce Kode Pembayaran plugin <= 1.1.4 - Reflected Cross Site Scripting (XSS) vulnerability | agenwebsite | AW WooCommerce Kode Pembayaran | High | 7.1 | 2025-03-03 13:30:04 | Deep Dive |
| CVE-2024-9212 | SKU Generator for WooCommerce <= 1.6.2 - Reflected Cross-Site Scripting | wpwham | SKU Generator for WooCommerce | Medium | 6.1 | 2025-03-01 04:21:50 | Deep Dive |
| CVE-2024-13750 | Multilevel Referral Affiliate Plugin for WooCommerce <= 2.28 - Authenticated (Subscriber+) SQL Injection | prismitsystems | Multilevel Referral Plugin for WooCommerce | Medium | 6.5 | 2025-03-01 04:21:49 | Deep Dive |
| CVE-2024-9217 | Currency Switcher for WooCommerce <= 2.16.2 - Reflected Cross-Site Scripting | wpwham | Currency Switcher for WooCommerce | Medium | 6.1 | 2025-03-01 04:21:48 | Deep Dive |
| CVE-2024-13358 | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages <= 3.4.24 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update | themekraft | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | Medium | 4.3 | 2025-03-01 03:22:19 | Deep Dive |