| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-5601 | WooCommerce Ninja Forms Product Add-ons < 1.7.1 - Unauthenticated Arbitrary File Upload | Unknown | WooCommerce Ninja Forms Product Add-ons | 高危 | - | 2023-11-06 20:41:49 | Deep Dive |
| CVE-2023-47186 | WordPress Kadence WooCommerce Email Designer plugin <= 1.5.11 - Cross Site Request Forgery (CSRF) vulnerability | StellarWP | Kadence WooCommerce Email Designer | Medium | 4.3 | 2023-11-06 11:25:24 | Deep Dive |
| CVE-2023-46783 | WordPress Pre-Orders for WooCommerce Plugin <= 1.2.13 is vulnerable to Cross Site Scripting (XSS) | Bright Plugins | Pre-Orders for WooCommerce | 中危 | - | 2023-11-06 09:26:18 | Deep Dive |
| CVE-2023-41685 | WordPress Woocommerce Support System plugin <= 1.2.1 - SQL Injection vulnerability | ilGhera | Woocommerce Support System | High | 7.6 | 2023-11-06 08:17:56 | Deep Dive |
| CVE-2023-35879 | WordPress WooCommerce Product Vendors plugin <= 2.1.78 - Shop Manager+ SQL Injection vulnerability | Woo | WooCommerce Product Vendors | High | 7.6 | 2023-10-31 14:20:23 | Deep Dive |
| CVE-2023-46094 | WordPress Conversios.io Plugin <= 6.5.3 is vulnerable to Cross Site Scripting (XSS) | Conversios | Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce | High | 7.1 | 2023-10-26 12:18:46 | Deep Dive |
| CVE-2023-46076 | WordPress WooCommerce PDF Invoice Builder Plugin <= 1.2.102 is vulnerable to Cross Site Scripting (XSS) | RedNao | WooCommerce PDF Invoice Builder, Create invoices, packing slips and more | High | 7.1 | 2023-10-26 12:05:36 | Deep Dive |
| CVE-2023-30492 | WordPress Minimum Purchase for WooCommerce Plugin <= 2.0.0.1 is vulnerable to Cross Site Scripting (XSS) | Vark | Minimum Purchase for WooCommerce | Medium | 6.5 | 2023-10-26 11:58:33 | Deep Dive |
| CVE-2023-4941 | BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 4.3 | 2023-10-20 07:29:29 | Deep Dive |
| CVE-2023-4926 | BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Deletion | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 5.4 | 2023-10-20 07:29:27 | Deep Dive |
| CVE-2023-4796 | Booster for WooCommerce <= 7.1.0 - Authenticated (Subscriber+) Information Disclosure via Shortcode | pluggabl | Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools | Medium | 4.3 | 2023-10-20 07:29:26 | Deep Dive |
| CVE-2023-4923 | BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Deletion | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 5.4 | 2023-10-20 07:29:22 | Deep Dive |
| CVE-2023-4924 | BEAR <= 1.1.3.3 - Missing Authorization to Product Deletion | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 5.4 | 2023-10-20 07:29:22 | Deep Dive |
| CVE-2023-4935 | BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Profile Creation | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 4.3 | 2023-10-20 06:35:28 | Deep Dive |
| CVE-2021-4353 | WooCommerce Dynamic Pricing and Discounts <= 2.4.1 - Unauthenticated Settings Import/Export | RightPress | WooCommerce Dynamic Pricing and Discounts | Medium | 5.3 | 2023-10-20 06:35:25 | Deep Dive |
| CVE-2023-4920 | BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 4.3 | 2023-10-20 06:35:23 | Deep Dive |
| CVE-2023-5414 | Icegram Express <= 5.6.23 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read | icegram | Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | Critical | 9.1 | 2023-10-20 06:35:20 | Deep Dive |
| CVE-2023-4937 | BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 4.3 | 2023-10-20 06:35:19 | Deep Dive |
| CVE-2023-4940 | BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 4.3 | 2023-10-20 06:35:16 | Deep Dive |
| CVE-2023-4943 | BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 4.3 | 2023-10-20 06:35:14 | Deep Dive |