| CVE-2024-32691 | WordPress Active Products Tables for WooCommerce plugin <= 1.0.6.2 - Broken Access Control vulnerability | realmag777 | Active Products Tables for WooCommerce | Medium | 5.3 | 2024-04-22 10:32:34 | Deep Dive |
| CVE-2024-1057 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | devitemsllc | ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin | Medium | 6.4 | 2024-04-20 01:56:38 | Deep Dive |
| CVE-2024-3731 | Customer Reviews for WooCommerce <= 5.47.0 - Reflected Cross-Site Scripting via 's' | ivole | Customer Reviews for WooCommerce | Medium | 6.1 | 2024-04-19 02:34:44 | Deep Dive |
| CVE-2023-6892 | EAN for WooCommerce <= 4.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via alg_wc_ean_product_meta Shortcode | wpcodefactory | EAN Barcode Generator for WooCommerce: UPC, ISBN & GTIN Inventory | Medium | 6.4 | 2024-04-18 11:05:29 | Deep Dive |
| CVE-2023-6897 | EAN for WooCommerce <= 4.9.2 - Insecure Direct Object Reference to Sensitve Information Exposure via Shortcode | wpcodefactory | EAN Barcode Generator for WooCommerce: UPC, ISBN & GTIN Inventory | Medium | 4.3 | 2024-04-18 11:05:29 | Deep Dive |
| CVE-2024-32602 | WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.3.3.1 - SQL Injection vulnerability | OnTheGoSystems | WooCommerce Multilingual & Multicurrency | High | 7.6 | 2024-04-18 10:25:58 | Deep Dive |
| CVE-2024-32584 | WordPress TeraWallet plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability | StandaloneTech | TeraWallet – For WooCommerce | Medium | 5.9 | 2024-04-18 09:14:25 | Deep Dive |
| CVE-2024-32585 | WordPress Import Content in WordPress & WooCommerce with Excel plugin <= 4.2 - Cross Site Scripting (XSS) vulnerability | extendWP | Import Content in WordPress & WooCommerce with Excel | Medium | 5.9 | 2024-04-18 09:12:49 | Deep Dive |
| CVE-2024-3333 | Essential Addons for Elementor <= 5.9.14 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute | wpdevteam | Essential Addons for Elementor – Popular Elementor Templates & Widgets | Medium | 6.4 | 2024-04-17 11:34:23 | Deep Dive |
| CVE-2024-32513 | WordPress Product Feed PRO for WooCommerce plugin <= 13.3.1 - Sensitive Data Exposure vulnerability | AdTribes.io | Product Feed PRO for WooCommerce | Medium | 5.3 | 2024-04-17 08:03:24 | Deep Dive |
| CVE-2024-32516 | WordPress Multi Currency For WooCommerce plugin <= 1.5.5 - Broken Access Control vulnerability | Palscode | Multi Currency For WooCommerce | Medium | 4.3 | 2024-04-17 07:40:21 | Deep Dive |
| CVE-2024-32517 | WordPress Custom Thank You Page Customize For WooCommerce by Binary Carpenter plugin <= 1.4.12 - Broken Access Control vulnerability | WooCommerce & WordPress Tutorials | Custom Thank You Page Customize For WooCommerce by Binary Carpenter | Medium | 4.3 | 2024-04-17 07:38:38 | Deep Dive |
| CVE-2024-32519 | WordPress GG Woo Feed for WooCommerce plugin <= 1.2.6 - Broken Access Control vulnerability | GutenGeek | GG Woo Feed for WooCommerce | Medium | 4.3 | 2024-04-17 07:34:53 | Deep Dive |
| CVE-2024-32520 | WordPress WPC Grouped Product for WooCommerce plugin <= 4.4.2 - Broken Access Control vulnerability | WPClever | WPC Grouped Product for WooCommerce | Medium | 4.3 | 2024-04-17 07:33:03 | Deep Dive |
| CVE-2024-32522 | WordPress Open Close WooCommerce Store plugin <= 4.9.1 - Broken Access Control vulnerability | Jaed Mosharraf & Pluginbazar Team | Open Close WooCommerce Store | Medium | 4.3 | 2024-04-17 07:31:47 | Deep Dive |
| CVE-2024-32524 | WordPress Custom Order Statuses for WooCommerce plugin <= 1.5.2 - Broken Access Control vulnerability | Nuggethon | Custom Order Statuses for WooCommerce | Medium | 4.3 | 2024-04-17 07:29:59 | Deep Dive |
| CVE-2024-3243 | Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending | ivole | Customer Reviews for WooCommerce | Medium | 4.3 | 2024-04-16 12:51:47 | Deep Dive |
| CVE-2024-3869 | Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Coupon Search | ivole | Customer Reviews for WooCommerce | Medium | 4.3 | 2024-04-16 12:51:46 | Deep Dive |
| CVE-2024-3067 | WooCommerce Google Feed Manager <= 2.4.2 - Authenticated (Admin+) SQL Injection to Reflected Cross-Site Scripting | aukejomm | WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping | High | 7.2 | 2024-04-16 12:51:45 | Deep Dive |
| CVE-2024-31431 | WordPress Product Input Fields for WooCommerce plugin <= 1.7.0 - Cross Site Request Forgery (CSRF) vulnerability | Tyche Softwares | Product Input Fields for WooCommerce | Medium | 4.3 | 2024-04-15 09:31:56 | Deep Dive |