| CVE-2024-11814 | Additional Custom Order Status for WooCommerce <= 1.6.0 - Reflected Cross-Site Scripting | wpcodefactory | Additional Custom Order Status for WooCommerce | Medium | 6.1 | 2024-12-04 09:24:21 | Deep Dive |
| CVE-2024-11418 | Additional Order Filters for WooCommerce <= 1.21 - Reflected Cross-Site Scripting | antonbond | Additional Order Filters for WooCommerce | Medium | 6.1 | 2024-11-26 03:31:56 | Deep Dive |
| CVE-2024-10828 | Advanced Order Export For WooCommerce <= 3.5.5 - Unauthenticated PHP Object Injection via Order Details | algolplus | Advanced Order Export For WooCommerce | High | 8.1 | 2024-11-13 03:20:07 | Deep Dive |
| CVE-2024-51693 | WordPress Search order by product SKU for WooCommerce plugin <= 0.2 - Reflected Cross Site Scripting (XSS) vulnerability | labdav | Search order by product SKU for WooCommerce | High | 7.1 | 2024-11-09 12:46:39 | Deep Dive |
| CVE-2024-10733 | code-projects Restaurant Order System login.php sql injection | code-projects | Restaurant Order System | High | 7.3 | 2024-11-03 12:00:07 | Deep Dive |
| CVE-2024-37201 | WordPress Woocommerce Customers Order History plugin <= 5.2.2 - Broken Access Control vulnerability | javmah | Woocommerce Customers Order History | Medium | 4.3 | 2024-11-01 14:18:35 | Deep Dive |
| CVE-2024-43253 | WordPress Smart Online Order for Clover plugin <= 1.5.6 - Broken Access Control vulnerability | ZAYTECH | Smart Online Order for Clover | Medium | 5.3 | 2024-11-01 14:17:36 | Deep Dive |
| CVE-2024-43254 | WordPress Smart Online Order for Clover plugin <= 1.5.6 - Broken Access Control vulnerability | ZAYTECH | Smart Online Order for Clover | Medium | 4.3 | 2024-11-01 14:17:36 | Deep Dive |
| CVE-2024-43343 | WordPress Order Tracking – WordPress Status Tracking Plugin plugin < 3.3.13 - Broken Access Control vulnerability | Etoile Web Design | Order Tracking | Medium | 4.3 | 2024-11-01 14:17:23 | Deep Dive |
| CVE-2024-10233 | SMSAlert - WooCommerce <= 3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_subscribe Shortcode | cozyvision1 | SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | Medium | 6.4 | 2024-10-29 11:01:36 | Deep Dive |
| CVE-2024-9686 | Order Notification for Telegram <= 1.0.1 - Missing Authorization to Unauthenticated Send Telegram Test Message | choplugins | Order Notification for Telegram | Medium | 5.3 | 2024-10-25 04:33:41 | Deep Dive |
| CVE-2024-9927 | WooCommerce Order Proposal <= 2.0.5 - Authenticated (Shop Manager+) Privilege Escalation via Order Proposal | WP Overnight BV | WooCommerce Order Proposal | High | 7.2 | 2024-10-23 02:06:04 | Deep Dive |
| CVE-2024-49321 | WordPress Simple Custom Post Order plugin <= 2.5.7 - Broken Access Control vulnerability | colorlibplugins | Simple Custom Post Order | - | - | 2024-10-21 11:11:02 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-8787 | Smart Online Order for Clover <= 1.5.7 - Reflected Cross-Site Scripting | elbanyaoui | Smart Online Order for Clover | Medium | 6.1 | 2024-10-16 02:05:02 | Deep Dive |
| CVE-2024-9895 | Smart Online Order for Clover <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via moo_receipt_link Shortcode | elbanyaoui | Smart Online Order for Clover | Medium | 6.4 | 2024-10-15 08:29:12 | Deep Dive |
| CVE-2024-9756 | Order Attachments for WooCommerce 2.0 - 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary File Upload | sldesignpl | Order Attachments for WooCommerce | Medium | 4.3 | 2024-10-12 06:51:10 | Deep Dive |
| CVE-2024-9377 | Products, Order & Customers Export for WooCommerce <= 2.0.15 - Reflected Cross-Site Scripting | wpcodefactory | Export Products, Orders & Customers for WooCommerce | Medium | 6.1 | 2024-10-10 02:06:09 | Deep Dive |
| CVE-2024-7873 | Stored XSS in Veribilim Software's Veribase Order Management | Veribilim Software | Veribase Order | 中危 | - | 2024-09-17 12:33:45 | Deep Dive |
| CVE-2024-43259 | WordPress Order Export for WooCommerce plugin <= 3.23 - Sensitive Data Exposure vulnerability | WebFactory | Order Export for WooCommerce | Medium | 5.3 | 2024-08-26 20:13:25 | Deep Dive |