| CVE-2024-5769 | MIMO Woocommerce Order Tracking <= 1.0.2 - Missing Authorization to Limited Settings Update | surakrai | MIMO Woocommerce Order Tracking | Medium | 4.3 | 2025-01-09 11:10:57 | Deep Dive |
| CVE-2024-12222 | Deliver via Shipos for WooCommerce <= 2.1.7 - Reflected Cross-Site Scripting via dvsfw_bulk_label_url Parameter | amitrotem | Deliver via Shipos for WooCommerce | Medium | 6.1 | 2025-01-09 11:10:56 | Deep Dive |
| CVE-2024-12337 | Shipping via Planzer for WooCommerce <= 1.0.25 - Reflected Cross-Site Scripting via processed-ids | webwirkung | Shipping via Planzer for WooCommerce | Medium | 6.1 | 2025-01-08 11:09:26 | Deep Dive |
| CVE-2024-11423 | Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch | WP Swings | Gift Cards for WooCommerce Pro | High | 7.5 | 2025-01-08 11:09:25 | Deep Dive |
| CVE-2025-22363 | WordPress Allada T-shirt Designer for Woocommerce plugin <= 1.1 - Broken Access Control vulnerability | Hermann LAHAMI | Allada T-shirt Designer for Woocommerce | Medium | 5.3 | 2025-01-07 16:57:15 | Deep Dive |
| CVE-2024-56272 | WordPress Hide Category by User Role for WooCommerce plugin <= 2.1.1 - Broken Access Control vulnerability | ThemeSupport | Hide Category by User Role for WooCommerce | Medium | 4.3 | 2025-01-07 16:46:33 | Deep Dive |
| CVE-2024-12532 | BWD Elementor Addons <= 4.3.18 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates | bestwpdeveloper | BWD Elementor Addons | Medium | 4.3 | 2025-01-07 11:11:12 | Deep Dive |
| CVE-2024-56290 | WordPress Multiple Shipping And Billing Address For Woocommerce Plugin <= 1.2 - Unauthenticated SQL Injection vulnerability | silverplugins217 | Multiple Shipping And Billing Address For Woocommerce | Critical | 9.3 | 2025-01-07 10:49:15 | Deep Dive |
| CVE-2025-22352 | WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerability | ELEXtensions | ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes | High | 7.6 | 2025-01-07 10:48:39 | Deep Dive |
| CVE-2024-12781 | Aurum - WordPress & WooCommerce Shopping Theme <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Demo Content Import | Laborator | Aurum - WordPress & WooCommerce Shopping Theme | Medium | 4.3 | 2025-01-07 06:40:59 | Deep Dive |
| CVE-2024-11725 | SMS Alert Order Notifications – WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update | cozyvision1 | SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | High | 8.8 | 2025-01-07 06:40:56 | Deep Dive |
| CVE-2024-12384 | Binary MLM Woocommerce <= 2.0 - Reflected Cross-Site Scripting via 'page' | letscms | Binary MLM For WooCommerce | Medium | 6.1 | 2025-01-07 05:24:10 | Deep Dive |
| CVE-2024-12438 | WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket <= 4.75 - Reflected Cross-Site Scripting | flickrocket | Digital Content Delivery (incl. DRM) by Flickrocket for WooCommerce | Medium | 6.1 | 2025-01-07 05:23:57 | Deep Dive |
| CVE-2024-12383 | Binary MLM Woocommerce <= 2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting | letscms | Binary MLM For WooCommerce | Medium | 6.1 | 2025-01-07 05:23:57 | Deep Dive |
| CVE-2024-11369 | Store credit / Gift cards for woocommerce <= 1.0.49.46 - Reflected Cross-Site Scripting | rajeshsingh520 | Store credit / Gift cards for woocommerce | Medium | 6.1 | 2025-01-07 05:23:53 | Deep Dive |
| CVE-2024-12435 | Compare Products for WooCommerce <= 3.2.1 - Reflected Cross-Site Scripting | a3rev | Compare Products for WooCommerce | Medium | 6.1 | 2025-01-07 04:22:23 | Deep Dive |
| CVE-2024-12313 | Compare Products for WooCommerce <= 3.2.1 - Unauthenticated PHP Object Injection | a3rev | Compare Products for WooCommerce | High | 8.1 | 2025-01-07 04:22:01 | Deep Dive |
| CVE-2024-11378 | Bizapp for WooCommerce <= 2.0.8 - Reflected Cross-Site Scripting | bizappventures | Bizapp for WooCommerce | Medium | 6.1 | 2025-01-07 04:21:59 | Deep Dive |
| CVE-2024-11465 | Custom Product Tabs for WooCommerce <= 1.8.5 - Authenticated (Shop Manager+) PHP Object Injection | eherman24 | Custom Product Tabs for WooCommerce | High | 7.2 | 2025-01-07 04:21:57 | Deep Dive |
| CVE-2024-12214 | WooCommerce HSS Extension for Streaming Video <= 3.31 - Reflected Cross-Site Scripting via videolink Parameter | hoststreamsell | WooCommerce HSS Extension for Streaming Video | Medium | 6.1 | 2025-01-07 04:21:57 | Deep Dive |