| CVE-2024-12334 | WC Affiliate – A Complete WooCommerce Affiliate Plugin <= 2.4 - Reflected Cross-Site Scripting | codexpert | WC Affiliate – WooCommerce Affiliate Plugin | Medium | 6.1 | 2025-01-26 11:09:45 | Deep Dive |
| CVE-2024-12826 | GoHero Store Customizer for WooCommerce <= 3.5 - Missing Authorization to Unuthenticated Settings Update | nmedia | GoHero Store Customizer for WooCommerce | Medium | 4.3 | 2025-01-25 07:24:20 | Deep Dive |
| CVE-2024-12600 | Custom Product Tabs Lite for WooCommerce <= 1.9.0 - Authenticated (Shop Manager+) PHP Object Injection | skyverge | Custom Product Tabs Lite for WooCommerce | High | 7.2 | 2025-01-25 06:40:39 | Deep Dive |
| CVE-2025-24755 | WordPress PDF Invoice Builder for WooCommerce plugin <= 4.6.0 - Cross Site Scripting (XSS) vulnerability | add-ons.org | PDF Invoice Builder for WooCommerce | Medium | 6.5 | 2025-01-24 17:25:22 | Deep Dive |
| CVE-2025-24705 | WordPress WooCommerce Quick View plugin <= 1.1.1 - Sensitive Data Exposure vulnerability | Arshid | WooCommerce Quick View | Medium | 5.3 | 2025-01-24 17:24:59 | Deep Dive |
| CVE-2025-24681 | WordPress Product Carousel Slider & Grid Ultimate for WooCommerce Plugin <= 1.10.0 - Cross Site Scripting (XSS) vulnerability | wpWax | Product Carousel Slider & Grid Ultimate for WooCommerce | Medium | 5.9 | 2025-01-24 17:24:54 | Deep Dive |
| CVE-2025-24668 | WordPress PPOM for WooCommerce plugin <= 33.0.8 - Cross Site Scripting (XSS) vulnerability | Themeisle | PPOM for WooCommerce | Medium | 5.9 | 2025-01-24 17:24:45 | Deep Dive |
| CVE-2025-24657 | WordPress Wishlist for WooCommerce plugin <=2.1.2 - Cross Site Scripting (XSS) vulnerability | WebToffee | Wishlist for WooCommerce | Medium | 5.9 | 2025-01-24 17:24:43 | Deep Dive |
| CVE-2025-24644 | WordPress WooCommerce PDF Invoices plugin <= 4.7.1 - Stored Cross Site Scripting (XSS) vulnerability | WebToffee | WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | Medium | 5.9 | 2025-01-24 17:24:43 | Deep Dive |
| CVE-2025-24647 | WordPress WooCommerce Cloak Affiliate Links plugin <= 1.0.35 - Cross Site Request Forgery (CSRF) vulnerability | datafeedr | WooCommerce Cloak Affiliate Links | Medium | 5.4 | 2025-01-24 17:24:42 | Deep Dive |
| CVE-2025-24625 | WordPress Taxonomy/Term and Role based Discounts for WooCommerce plugin <= 5.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | Naked Cat Plugins | Taxonomy/Term and Role based Discounts for WooCommerce | Medium | 4.3 | 2025-01-24 17:24:41 | Deep Dive |
| CVE-2025-24633 | WordPress Build Private Store For Woocommerce plugin <= 1.0 - Broken Access Control vulnerability | silverplugins217 | Build Private Store For Woocommerce | Medium | 5.3 | 2025-01-24 17:24:34 | Deep Dive |
| CVE-2025-24596 | WordPress WooCommerce Product Table Lite plugin <= 3.8.7 - Broken Access Control vulnerability | WC Product Table | WooCommerce Product Table Lite | Medium | 5.3 | 2025-01-24 17:24:31 | Deep Dive |
| CVE-2025-24594 | WordPress Linet ERP-Woocommerce Integration plugin <= 3.5.7 - CSRF to Broken Access Control vulnerability | aribhour | Linet ERP-Woocommerce Integration | Medium | 6.5 | 2025-01-24 17:24:29 | Deep Dive |
| CVE-2025-23991 | WordPress Product Size Charts Plugin for WooCommerce plugin <= 2.4.5 - Broken Access Control vulnerability | Dotstore | Product Size Charts Plugin for WooCommerce | Medium | 4.3 | 2025-01-24 15:31:41 | Deep Dive |
| CVE-2024-13511 | Variation Swatches for WooCommerce 1.0.8 - 1.3.2 - Cross-Site Request Forgery to Plugin Settings Reset | themehunk | Variation Swatches for WooCommerce | Medium | 4.3 | 2025-01-23 09:21:09 | Deep Dive |
| CVE-2025-23966 | WordPress a Gateway for Pasargad Bank on WooCommerce Plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerability | Ala Falaki | a Gateway for Pasargad Bank on WooCommerce | High | 7.1 | 2025-01-22 14:29:27 | Deep Dive |
| CVE-2025-23495 | WordPress WooCommerce Order Search plugin <= 1.1.0 - Reflected Cross Site Scripting (XSS) vulnerability | Chetan Khandla | WooCommerce Order Search | High | 7.1 | 2025-01-22 14:29:13 | Deep Dive |
| CVE-2025-22318 | WordPress Standard Box Sizes plugin <= 1.6.13 - Broken Access Control vulnerability | enituretechnology | Standard Box Sizes – for WooCommerce | High | 7.5 | 2025-01-21 13:40:34 | Deep Dive |
| CVE-2024-13317 | ShipWorks Connector for Woocommerce <= 5.2.5 - Cross-Site Request Forgery to Service Password/Username Update | advancedcreation | ShipWorks Connector for Woocommerce | Medium | 4.3 | 2025-01-18 07:05:08 | Deep Dive |