| CVE-2025-30807 | WordPress Next-Cart Store to WooCommerce Migration plugin <= 3.9.4 - SQL Injection vulnerability | Martin Nguyen | Next-Cart Store to WooCommerce Migration | Critical | 9.3 | 2025-04-01 20:58:07 | Deep Dive |
| CVE-2025-31854 | WordPress Simple Sticky Add To Cart For WooCommerce plugin <= 1.4.9 - Broken Access Control vulnerability | Sharaz Shahid | Simple Sticky Add To Cart For WooCommerce | Medium | 4.3 | 2025-04-01 14:52:02 | Deep Dive |
| CVE-2025-31084 | WordPress Sunshine Photo Cart plugin <= 3.4.10 - PHP Object Injection Vulnerability | sunshinephotocart | Sunshine Photo Cart | Critical | 9.8 | 2025-04-01 05:31:42 | Deep Dive |
| CVE-2025-30791 | WordPress Cart tracking for WooCommerce plugin <= 1.0.16 - SQL Injection Vulnerability | wpdever | Cart tracking for WooCommerce | High | 7.6 | 2025-03-27 10:54:51 | Deep Dive |
| CVE-2025-26899 | WordPress Recapture for WooCommerce Plugin <= 1.0.43 - CSRF to Settings Change vulnerability | Recapture Cart Recovery and Email Marketing | Recapture for WooCommerce | Medium | 6.5 | 2025-03-15 21:57:02 | Deep Dive |
| CVE-2025-0956 | WooCommerce Recover Abandoned Cart <= 24.4.0 - Unauthenticated PHP Object Injection | FantasticPlugins | WooCommerce Recover Abandoned Cart | High | 8.1 | 2025-03-05 09:21:44 | Deep Dive |
| CVE-2025-23829 | WordPress Woo Update Variations In Cart plugin <= 0.0.9 - Cross Site Scripting (XSS) vulnerability | codingkart | Woo Update Variations In Cart | Medium | 6.5 | 2025-03-03 13:30:19 | Deep Dive |
| CVE-2024-10563 | WooCommerce Cart Count Shortcode < 1.1.0 - Contributor+ XSS | Unknown | WooCommerce Cart Count Shortcode | 中危 | - | 2025-02-26 06:00:06 | Deep Dive |
| CVE-2024-13795 | Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactivation Message | ecwid | Ecwid by Lightspeed Ecommerce Shopping Cart | Medium | 4.3 | 2025-02-18 07:28:14 | Deep Dive |
| CVE-2024-10591 | MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics <= 1.5.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update | makewebbetter | MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics | High | 8.8 | 2025-01-30 13:42:09 | Deep Dive |
| CVE-2025-23471 | WordPress ECT Add to Cart Button plugin <= 1.4 - CSRF to Stored XSS vulnerability | etemplates | ECT Add to Cart Button | High | 7.1 | 2025-01-16 20:06:01 | Deep Dive |
| CVE-2024-12712 | Shopping Cart & eCommerce Store <= 5.7.8 - Missing Authorization to Order Updates | levelfourstorefront | Shopping Cart & eCommerce Store | Medium | 5.3 | 2025-01-08 09:18:36 | Deep Dive |
| CVE-2024-12622 | WordPress Simple Shopping Cart <= 5.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | mra13 | Simple Shopping Cart | Medium | 6.4 | 2024-12-24 05:23:44 | Deep Dive |
| CVE-2024-54386 | WordPress Push Monkey Pro plugin <= 3.9 - CSRF to Stored XSS vulnerability | pushmonkey | Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart | High | 7.1 | 2024-12-16 14:14:08 | Deep Dive |
| CVE-2024-12517 | WooCommerce Cart Count Shortcode <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | prontotools | WooCommerce Cart Count Shortcode | Medium | 6.4 | 2024-12-14 04:23:43 | Deep Dive |
| CVE-2023-41671 | WordPress Abandoned Cart Lite for WooCommerce plugin <= 5.16.1 - Cross Site Request Forgery (CSRF) vulnerability | tychesoftwares | Abandoned Cart Lite for WooCommerce | 中危 | - | 2024-12-13 14:24:12 | Deep Dive |
| CVE-2023-34376 | WordPress Change WooCommerce Add To Cart Button Text plugin <= 1.3 - Broken Access Control vulnerability | Sekander Badsha | Change WooCommerce Add To Cart Button Text | Medium | 5.4 | 2024-12-13 14:23:37 | Deep Dive |
| CVE-2022-45826 | WordPress Sunshine Photo Cart plugin <= 2.9.13 - Auth. Broken Access Control vulnerability | WP Sunshine | Sunshine Photo Cart | Medium | 5.4 | 2024-12-13 14:22:04 | Deep Dive |
| CVE-2023-47694 | WordPress Mini Cart Drawer For WooCommerce plugin <= 4.0.0 - Broken Access Control vulnerability | appsbd | Mini Cart Drawer For WooCommerce | Medium | 5.4 | 2024-12-09 11:30:54 | Deep Dive |
| CVE-2024-12128 | Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal <= 3.1.2 - Reflected Cross-Site Scripting via monthly_sales_current_year Parameter | nshowketgmailcom | Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal | Medium | 6.1 | 2024-12-07 09:27:06 | Deep Dive |