| CVE-2024-32814 | WordPress Advanced Local Pickup for WooCommerce plugin <= 1.6.1 - Broken Access Control vulnerability | Zorem | Advanced Local Pickup for WooCommerce | Medium | 5.3 | 2024-06-09 12:40:18 | Deep Dive |
| CVE-2024-31267 | WordPress Flexible Checkout Fields for WooCommerce plugin <= 4.1.2 - Broken Access Control vulnerability | WP Desk | Flexible Checkout Fields for WooCommerce | Medium | 4.3 | 2024-06-09 11:14:37 | Deep Dive |
| CVE-2024-30470 | WordPress YITH WooCommerce Account Funds Premium plugin <= 1.32.0 - Broken Access Control vulnerability | YITH | YITH WooCommerce Account Funds Premium | Medium | 6.5 | 2024-06-09 10:51:39 | Deep Dive |
| CVE-2024-30466 | WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.3.4 - Broken Access Control vulnerability | OnTheGoSystems | WooCommerce Multilingual & Multicurrency | Medium | 5.4 | 2024-06-09 10:43:57 | Deep Dive |
| CVE-2024-25929 | WordPress Product Catalog Mode For Woocommerce plugin <= 5.0.5 - Broken Access Control vulnerability | MultiVendorX | Product Catalog Enquiry for WooCommerce by MultiVendorX | Medium | 6.5 | 2024-06-09 10:30:17 | Deep Dive |
| CVE-2023-34003 | WordPress WooCommerce Box Office plugin <= 1.1.51 - Unauthenticated Save Ticket Barcode vulnerability | Woo | WooCommerce Box Office | Medium | 6.5 | 2024-06-09 10:19:05 | Deep Dive |
| CVE-2023-51494 | WordPress WooCommerce Product Vendors plugin <= 2.2.1 - Broken Access Control vulnerability | Woo | WooCommerce Product Vendors | Medium | 5.3 | 2024-06-09 09:10:07 | Deep Dive |
| CVE-2023-52230 | WordPress Booster Plus for WooCommerce plugin < 7.1.3 - Authenticated Arbitrary WordPress Option Disclosure Vulnerability | Pluggabl LLC | Booster Plus for WooCommerce | Medium | 6.5 | 2024-06-09 09:08:28 | Deep Dive |
| CVE-2023-52232 | WordPress Booster Plus for WooCommerce plugin < 7.1.2 - Authenticated Arbitrary Post/Page Deletion Vulnerability | Pluggabl LLC | Booster Plus for WooCommerce | Medium | 6.5 | 2024-06-09 09:06:31 | Deep Dive |
| CVE-2024-30537 | WordPress WPC Badge Management for WooCommerce plugin <= 2.4.0 - Broken Access Control vulnerability | WPClever | WPC Badge Management for WooCommerce | Medium | 4.3 | 2024-06-09 09:01:58 | Deep Dive |
| CVE-2024-31098 | WordPress New Order Notification for Woocommerce plugin <= 2.0.2 - Broken Access Control vulnerability | Mr.Ebabi | New Order Notification for Woocommerce | High | 8.1 | 2024-06-09 08:58:36 | Deep Dive |
| CVE-2024-35698 | WordPress YITH WooCommerce Tab Manager plugin <= 1.35.0 - Cross Site Scripting (XSS) vulnerability | YITHEMES | YITH WooCommerce Tab Manager | Medium | 5.9 | 2024-06-08 14:19:22 | Deep Dive |
| CVE-2024-35730 | WordPress Active Products Tables for WooCommerce plugin <= 1.0.6.3 - Reflected Cross Site Scripting (XSS) vulnerability | realmag777 | Active Products Tables for WooCommerce | High | 7.1 | 2024-06-08 12:54:56 | Deep Dive |
| CVE-2024-35733 | WordPress Auto Coupons for WooCommerce plugin <= 3.0.14 - Reflected Cross Site Scripting (XSS) vulnerability | RLDD | Auto Coupons for WooCommerce | High | 7.1 | 2024-06-08 12:50:24 | Deep Dive |
| CVE-2024-1689 | WooCommerce Tools <= 1.2.9 - Missing Authorization to Authenticated (Subscriber+) Plugin Module Deactivation | themefarmer | WooCommerce Tools | Medium | 4.3 | 2024-06-07 02:02:37 | Deep Dive |
| CVE-2024-5188 | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting | wpdevteam | Essential Addons for Elementor – Popular Elementor Templates & Widgets | Medium | 6.4 | 2024-06-06 11:03:03 | Deep Dive |
| CVE-2024-5259 | MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace Solutions | Medium | 6.4 | 2024-06-06 09:34:02 | Deep Dive |
| CVE-2024-5665 | Login/Signup Popup ( Inline Form + Woocommerce ) 2.7.1 - 2.7.2 - Missing Authorization to Arbitrary Options Exposure | xootix | Login/Signup Popup ( Inline Form + Woocommerce ) | Medium | 4.3 | 2024-06-06 07:37:12 | Deep Dive |
| CVE-2024-4608 | SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | artbees | SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster | Medium | 6.4 | 2024-06-06 03:32:53 | Deep Dive |
| CVE-2024-5324 | XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update | xootix | Waitlist Woocommerce ( Back in stock notifier ) | High | 8.8 | 2024-06-06 02:02:48 | Deep Dive |