| CVE-2024-31920 | WordPress Currency per Product for WooCommerce plugin <= 1.6.0 - Cross Site Request Forgery (CSRF) vulnerability | Tyche Softwares | Currency per Product for WooCommerce | Medium | 4.3 | 2024-04-15 09:27:55 | Deep Dive |
| CVE-2024-31940 | WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.104 - Cross Site Request Forgery (CSRF) vulnerability | RedNao | Extra Product Options Builder for WooCommerce | Medium | 4.3 | 2024-04-15 09:15:47 | Deep Dive |
| CVE-2024-32095 | WordPress MultiParcels Shipping For WooCommerce plugin < 1.16.9 - Cross Site Request Forgery (CSRF) vulnerability | MultiParcels | MultiParcels Shipping For WooCommerce | Medium | 4.3 | 2024-04-15 08:57:05 | Deep Dive |
| CVE-2024-32101 | WordPress Email Marketing for WooCommerce plugin <= 1.14.3 - Cross Site Request Forgery (CSRF) vulnerability | Omnisend | Email Marketing for WooCommerce by Omnisend | Medium | 4.3 | 2024-04-15 08:49:01 | Deep Dive |
| CVE-2024-32434 | WordPress Order Delivery Date for WooCommerce plugin <= 3.20.2 - Cross Site Request Forgery (CSRF) vulnerability | Tyche Softwares | Order Delivery Date for WooCommerce | Medium | 4.3 | 2024-04-15 08:10:32 | Deep Dive |
| CVE-2024-32446 | WordPress Wallet System for WooCommerce plugin <= 2.5.9 - Cross Site Request Forgery (CSRF) vulnerability | WP Swings | Wallet System for WooCommerce | Medium | 5.4 | 2024-04-15 07:57:52 | Deep Dive |
| CVE-2024-32087 | WordPress Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and More plugin <= 3.5.7 - Auth. SQL Injection (SQLi) vulnerability | ExportFeed.com | Product Feed on WooCommerce for Google | High | 7.6 | 2024-04-15 07:40:55 | Deep Dive |
| CVE-2024-1310 | WooCommerce < 8.6 - Contributor+ Private/Draft Products Access | Unknown | WooCommerce | - | - | 2024-04-15 05:00:04 | Deep Dive |
| CVE-2024-0399 | WooCommerce Customers Manager < 29.7 - Subscriber+ SQL Injection | Unknown | WooCommerce Customers Manager | - | - | 2024-04-15 05:00:02 | Deep Dive |
| CVE-2023-6494 | WPC Smart Quick View for WooCommerce <= 4.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting | wpclever | WPC Smart Quick View for WooCommerce | Medium | 4.4 | 2024-04-13 08:41:16 | Deep Dive |
| CVE-2023-51499 | WordPress WooCommerce Shipping Per Product plugin <= 2.5.4 - Broken Access Control vulnerability | WooCommerce | WooCommerce Shipping Per Product | Medium | 4.3 | 2024-04-12 14:37:00 | Deep Dive |
| CVE-2024-31262 | WordPress WooCommerce Checkout Field Editor (Checkout Manager) plugin <= 2.1.8 - Cross Site Request Forgery (CSRF) vulnerability | Jcodex | WooCommerce Checkout Field Editor (Checkout Manager) | Medium | 5.4 | 2024-04-12 12:49:48 | Deep Dive |
| CVE-2024-31364 | WordPress ELEX WooCommerce Dynamic Pricing and Discounts plugin <= 2.1.2 - Cross Site Request Forgery (CSRF) vulnerability | ELEXtensions | ELEX WooCommerce Dynamic Pricing and Discounts | Medium | 4.3 | 2024-04-12 12:19:10 | Deep Dive |
| CVE-2024-0881 | Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access | Unknown | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel | - | - | 2024-04-11 15:36:31 | Deep Dive |
| CVE-2024-32105 | WordPress ELEX WooCommerce Dynamic Pricing and Discounts plugin <= 2.1.2 - Cross Site Request Forgery (CSRF) vulnerability | ELEXtensions | ELEX WooCommerce Dynamic Pricing and Discounts | Medium | 4.3 | 2024-04-11 13:16:23 | Deep Dive |
| CVE-2024-31430 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR and WOLF WordPress plugins | realmag777 | WOLF – WordPress Posts Bulk Editor and Manager Professional | Medium | 4.3 | 2024-04-10 19:10:02 | Deep Dive |
| CVE-2024-31943 | WordPress USPS Shipping for WooCommerce plugin <= 1.9.2 - Cross Site Request Forgery (CSRF) vulnerability | Octolize | USPS Shipping for WooCommerce – Live Rates | Medium | 4.3 | 2024-04-10 17:41:07 | Deep Dive |
| CVE-2024-31944 | WordPress WooCommerce UPS Shipping plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerability | Octolize | WooCommerce UPS Shipping – Live Rates and Access Points | Medium | 4.3 | 2024-04-10 17:39:55 | Deep Dive |
| CVE-2024-31297 | WordPress Wholesale For WooCommerce plugin <= 2.3.1 - Unauthenticated Arbitrary Post/Page vulnerability | WPExperts | Wholesale For WooCommerce | High | 7.5 | 2024-04-10 15:58:56 | Deep Dive |
| CVE-2024-3020 | Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection | shapedplugin | Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel | High | 7.2 | 2024-04-10 04:30:22 | Deep Dive |