| CVE-2024-1807 | Product Sort and Display for WooCommerce <= 2.4.1 - Missing Authorization | a3rev | Product Sort and Display for WooCommerce | Medium | 6.5 | 2024-04-02 09:32:10 | Deep Dive |
| CVE-2024-31117 | WordPress WooCommerce Bookings Calendar plugin <= 1.0.36 - Cross Site Scripting (XSS) vulnerability | Moises Heberle | WooCommerce Bookings Calendar | Medium | 6.5 | 2024-03-31 18:51:17 | Deep Dive |
| CVE-2024-31100 | WordPress Popup Cart Lite for WooCommerce plugin <= 1.1 - Cross Site Request Forgery (CSRF) vulnerability | Festi-Team | Popup Cart Lite for WooCommerce | Medium | 5.4 | 2024-03-31 18:26:31 | Deep Dive |
| CVE-2024-3018 | Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword | wpdevteam | Essential Addons for Elementor – Popular Elementor Templates & Widgets | High | 8.8 | 2024-03-30 11:17:26 | Deep Dive |
| CVE-2024-30462 | WordPress HUSKY plugin <= 1.3.5.1 - Cross Site Request Forgery (CSRF) vulnerability | realmag777 | HUSKY – Products Filter for WooCommerce (formerly WOOF) | Medium | 4.3 | 2024-03-29 16:24:54 | Deep Dive |
| CVE-2024-30477 | WordPress Klarna Payments for WooCommerce plugin <= 3.2.4 - Broken Access Control vulnerability | klarna | Klarna Payments for WooCommerce | Medium | 5.3 | 2024-03-29 16:01:17 | Deep Dive |
| CVE-2024-30518 | WordPress Custom WooCommerce Checkout Fields Editor plugin <= 1.3.0 - Cross Site Request Forgery (CSRF) vulnerability | ThemeLocation | Custom WooCommerce Checkout Fields Editor | Medium | 4.3 | 2024-03-29 15:54:43 | Deep Dive |
| CVE-2024-30469 | WordPress Wholesale For WooCommerce plugin <= 2.3.0 - Unauthenticated Sensitive Data Exposure vulnerability | WPExperts | Wholesale For WooCommerce | Medium | 5.3 | 2024-03-29 15:47:05 | Deep Dive |
| CVE-2024-30511 | WordPress FG PrestaShop to WooCommerce plugin <= 4.45.1 - Sensitive Data Exposure via Log File vulnerability | Frédéric GILLES | FG PrestaShop to WooCommerce | Medium | 5.3 | 2024-03-29 15:42:44 | Deep Dive |
| CVE-2024-30458 | WordPress FOX – Currency Switcher Professional for WooCommerce plugin <= 1.4.1.7 - Cross Site Request Forgery (CSRF) vulnerability | realmag777 | WOOCS – WooCommerce Currency Switcher | Medium | 4.3 | 2024-03-29 13:05:15 | Deep Dive |
| CVE-2024-3061 | HUSKY – Products Filter Professional for WooCommerce <= 1.3.5.2 - Authenticated (Admin+) Local File Inclusion | realmag777 | HUSKY – Products Filter Professional for WooCommerce | High | 7.2 | 2024-03-29 09:31:07 | Deep Dive |
| CVE-2024-0956 | WP ERP <= 1.13.0 - Authenticated (AccountingManager+) SQL Injection | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | Medium | 4.9 | 2024-03-29 06:44:03 | Deep Dive |
| CVE-2024-0609 | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Unauthenticated Stored Cross-Site Scripting | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | High | 7.2 | 2024-03-29 06:44:02 | Deep Dive |
| CVE-2024-0608 | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (Subscriber+) SQL Injection | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | Medium | 6.5 | 2024-03-29 06:44:01 | Deep Dive |
| CVE-2024-0913 | WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | High | 7.2 | 2024-03-29 06:44:00 | Deep Dive |
| CVE-2024-27999 | WordPress Preview E-mails for WooCommerce plugin <= 2.2.1 - Reflected Cross Site Scripting (XSS) vulnerability | Digamber Pradhan | Preview E-mails for WooCommerce | High | 7.1 | 2024-03-28 06:50:53 | Deep Dive |
| CVE-2023-52231 | WordPress Booster Plus for WooCommerce plugin < 7.1.2 - Auth. Sensitive Data Exposure vulnerability | Booster | Booster Plus for WooCommerce | Medium | 6.5 | 2024-03-28 06:36:43 | Deep Dive |
| CVE-2023-52234 | WordPress Booster Elite for WooCommerce plugin < 7.1.2 - Auth. Sensitive Data Exposure vulnerability | Booster | Booster Elite for WooCommerce | Medium | 6.5 | 2024-03-28 06:34:49 | Deep Dive |
| CVE-2024-30230 | WordPress PDF Invoices and Packing Slips For WooCommerce plugin <= 1.3.7 - PHP Object Injection vulnerability | Acowebs | PDF Invoices and Packing Slips For WooCommerce | High | 8.2 | 2024-03-28 04:47:05 | Deep Dive |
| CVE-2023-44999 | WordPress WooCommerce Stripe Gateway plugin <= 7.6.0 - Cross Site Request Forgery (CSRF) vulnerability | WooCommerce | WooCommerce Stripe Payment Gateway | Medium | 5.4 | 2024-03-27 13:27:46 | Deep Dive |