| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-0617 | Category Discount Woocommerce <= 4.12 - Missing Authorization via wpcd_save_discount() | vidishp | Simple Discount Rules for Woocommerce | Medium | 5.3 | 2024-01-25 01:55:02 | Deep Dive |
| CVE-2024-22135 | WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload | WebToffee | Order Export & Order Import for WooCommerce | High | 8.0 | 2024-01-24 11:51:38 | Deep Dive |
| CVE-2024-22152 | WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload | WebToffee | Product Import Export for WooCommerce | High | 8.0 | 2024-01-24 11:48:56 | Deep Dive |
| CVE-2023-6626 | Product Enquiry for WooCommerce < 3.1 - Admin+ Stored XSS | Unknown | Product Enquiry for WooCommerce | 中危 | - | 2024-01-22 19:14:28 | Deep Dive |
| CVE-2023-6625 | Product Enquiry for WooCommerce < 3.1 - Arbitrary Enquiry Deletion via CSRF | Unknown | Product Enquiry for WooCommerce | 中危 | - | 2024-01-22 19:14:24 | Deep Dive |
| CVE-2022-40700 | Server Side Request Forgery (SSRF) vulnerability affecting multiple WordPress plugins | Montonio | Montonio for WooCommerce | High | 8.2 | 2024-01-19 14:30:11 | Deep Dive |
| CVE-2024-0705 | Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection | themehigh | Payment Gateway of Stripe for WooCommerce | Critical | 9.8 | 2024-01-19 09:31:18 | Deep Dive |
| CVE-2022-40702 | WordPress Advanced Local Pickup for WooCommerce Plugin <= 1.5.2 is vulnerable to Broken Access Control | Zorem | Advanced Local Pickup for WooCommerce | Medium | 5.4 | 2024-01-17 16:51:06 | Deep Dive |
| CVE-2023-34379 | WordPress Cart2Cart: Magento to WooCommerce Migration Plugin <= 2.0.0 is vulnerable to Broken Access Control | MagneticOne | Cart2Cart: Magento to WooCommerce Migration | Medium | 5.4 | 2024-01-17 16:12:05 | Deep Dive |
| CVE-2022-40203 | WordPress Advanced Dynamic Pricing for WooCommerce Plugin <= 4.1.5 is vulnerable to Broken Access Control | AlgolPlus | Advanced Dynamic Pricing for WooCommerce | Medium | 6.3 | 2024-01-17 16:08:58 | Deep Dive |
| CVE-2022-38141 | WordPress Sales Report Email for WooCommerce Plugin <= 2.8 is vulnerable to Broken Access Control | Zorem | Sales Report Email for WooCommerce | Medium | 4.3 | 2024-01-17 16:04:02 | Deep Dive |
| CVE-2023-7151 | Product Enquiry for WooCommerce < 3.2 - Reflected XSS | Unknown | Product Enquiry for WooCommerce | 中危 | - | 2024-01-16 15:57:53 | Deep Dive |
| CVE-2023-4703 | All in One B2B for WooCommerce <= 1.0.3 - Unauthenticated Privilege Escalation | Unknown | All in One B2B for WooCommerce | 中危 | - | 2024-01-16 15:56:47 | Deep Dive |
| CVE-2023-0479 | Print Invoice & Delivery Notes for WooCommerce < 4.7.2 - Reflected XSS | Unknown | Print Invoice & Delivery Notes for WooCommerce | 中危 | - | 2024-01-16 15:55:08 | Deep Dive |
| CVE-2023-0079 | Customer Reviews for WooCommerce < 5.17.0 - Contributor+ Stored XSS | Unknown | Customer Reviews for WooCommerce | - | - | 2024-01-16 15:54:59 | Deep Dive |
| CVE-2022-0775 | WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion | Unknown | WooCommerce | 中危 | - | 2024-01-16 15:52:37 | Deep Dive |
| CVE-2022-1563 | WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure | Unknown | wp-graphql-woocommerce | 中危 | - | 2024-01-16 15:50:08 | Deep Dive |
| CVE-2023-4960 | WCFM Marketplace <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | wclovers | WCFM Marketplace – Multivendor Marketplace for WooCommerce | Medium | 6.4 | 2024-01-11 08:33:10 | Deep Dive |
| CVE-2023-6638 | GTG Product Feed for Shopping <= 1.2.4 - Missing Authorization to Unauthenticated Plugin Settings Update | wpopal | GG Woo Feed for WooCommerce Shopping Feed on Google and Other Channels | Medium | 6.5 | 2024-01-11 08:33:01 | Deep Dive |
| CVE-2023-6645 | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 - Authenticated (Contributor+) Cross-Site Scripting | pickplugins | Post Grid | Medium | 6.4 | 2024-01-11 08:32:50 | Deep Dive |