| CVE-2023-4947 | WooCommerce EAN Payment Gateway < 6.1.0 - Missing Authorization to Authenticated (Contributor+) EAN Update | Yan&Co | WooCommerce EAN Payment Gateway | Medium | 4.3 | 2023-10-20 06:35:13 | Deep Dive |
| CVE-2023-4942 | BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 4.3 | 2023-10-20 06:35:12 | Deep Dive |
| CVE-2023-5638 | Booster for WooCommerce <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | pluggabl | Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools | Medium | 6.4 | 2023-10-19 01:53:51 | Deep Dive |
| CVE-2023-45072 | WordPress Order auto complete for WooCommerce Plugin <= 1.2.0 is vulnerable to Cross Site Scripting (XSS) | Kardi | Order auto complete for WooCommerce | Medium | 5.9 | 2023-10-18 12:43:01 | Deep Dive |
| CVE-2023-4938 | BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation | realmag777 | BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | Medium | 4.3 | 2023-10-18 07:31:17 | Deep Dive |
| CVE-2023-45006 | WordPress WooODT Lite Plugin <= 2.4.6 is vulnerable to Cross Site Scripting (XSS) | ByConsole | WooODT Lite – WooCommerce Order Delivery or Pickup with Date Time Location | High | 7.1 | 2023-10-17 11:24:12 | Deep Dive |
| CVE-2023-4821 | Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting | Unknown | Drag and Drop Multiple File Upload for WooCommerce | 中危 | - | 2023-10-16 19:39:24 | Deep Dive |
| CVE-2023-44986 | WordPress Abandoned Cart Lite for WooCommerce Plugin <= 5.15.2 is vulnerable to Cross Site Scripting (XSS) | Tyche Softwares | Abandoned Cart Lite for WooCommerce | Medium | 5.9 | 2023-10-16 10:50:01 | Deep Dive |
| CVE-2023-45638 | WordPress Eupago Gateway For Woocommerce Plugin <= 3.1.9 is vulnerable to Cross Site Request Forgery (CSRF) | euPago | Eupago Gateway For Woocommerce | Medium | 6.5 | 2023-10-16 08:59:06 | Deep Dive |
| CVE-2023-44995 | WordPress WooCommerce Login Redirect Plugin <= 2.2.4 is vulnerable to Cross Site Request Forgery (CSRF) | WP Doctor | WooCommerce Login Redirect | Medium | 5.4 | 2023-10-10 15:46:49 | Deep Dive |
| CVE-2023-44260 | WordPress Woocommerce ESTO Plugin <= 2.23.1 is vulnerable to Cross Site Request Forgery (CSRF) | Mikk Mihkel Nurges, Rebing OÜ | Woocommerce ESTO | Medium | 4.3 | 2023-10-09 08:35:07 | Deep Dive |
| CVE-2023-40559 | WordPress WooCommerce Dynamic Pricing and Discount Rules Plugin <= 2.4.0 is vulnerable to Cross Site Request Forgery (CSRF) | theDotstore | Dynamic Pricing and Discount Rules for WooCommerce | Medium | 4.3 | 2023-10-04 14:11:09 | Deep Dive |
| CVE-2023-40561 | Enhanced Ecommerce Google Analytics for WooCommerce | theDotstore | Enhanced Ecommerce Google Analytics for WooCommerce | Medium | 5.4 | 2023-10-04 13:55:25 | Deep Dive |
| CVE-2023-25788 | WordPress Saphali Woocommerce Lite Plugin <= 1.8.13 is vulnerable to Cross Site Request Forgery (CSRF) | Saphali | Saphali Woocommerce Lite | Medium | 6.3 | 2023-10-04 10:30:56 | Deep Dive |
| CVE-2023-39158 | WordPress Woocommerce Category Banner Management Plugin <= 2.4.2 is vulnerable to Cross Site Request Forgery (CSRF) | theDotstore | Banner Management For WooCommerce | Medium | 4.3 | 2023-10-03 13:20:37 | Deep Dive |
| CVE-2023-39159 | WordPress Fraud Prevention For Woocommerce Plugin <= 2.1.5 is vulnerable to Cross Site Request Forgery (CSRF) | theDotstore | Fraud Prevention For Woocommerce | Medium | 4.3 | 2023-10-03 12:39:48 | Deep Dive |
| CVE-2023-40212 | WordPress WooCommerce Product Attachment Plugin <= 2.1.8 is vulnerable to Cross Site Request Forgery (CSRF) | theDotstore | Product Attachment for WooCommerce | Medium | 4.3 | 2023-10-03 12:36:45 | Deep Dive |
| CVE-2023-44144 | WordPress Dreamfox Media Payment gateway per Product for Woocommerce Plugin <= 3.2.7 is vulnerable to Cross Site Scripting (XSS) | Dreamfox | Payment gateway per Product for WooCommerce | High | 7.1 | 2023-10-02 09:43:01 | Deep Dive |
| CVE-2023-41691 | WordPress WooCommerce PensoPay Plugin <= 6.3.1 is vulnerable to Cross Site Scripting (XSS) | Pensopay | WooCommerce PensoPay | High | 7.1 | 2023-09-29 13:56:01 | Deep Dive |
| CVE-2023-5230 | TM WooCommerce Compare & Wishlist <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | templatemonster-2002 | TM WooCommerce Compare & Wishlist | Medium | 6.4 | 2023-09-28 04:31:35 | Deep Dive |