| CVE-2022-46856 | WordPress Woocommerce Product Designer Plugin <= 4.3.3 is vulnerable to Cross Site Request Forgery (CSRF) | ORION | Woocommerce Products Designer | Medium | 5.4 | 2023-05-25 11:23:58 | Deep Dive |
| CVE-2022-46810 | WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF) | VillaTheme | Thank You Page Customizer for WooCommerce – Increase Your Sales | Medium | 4.3 | 2023-05-25 11:18:45 | Deep Dive |
| CVE-2022-45367 | WordPress Custom Order Numbers for WooCommerce Plugin <= 1.4.0 is vulnerable to Cross Site Request Forgery (CSRF) | Tyche Softwares | Custom Order Numbers for WooCommerce | Medium | 4.3 | 2023-05-25 09:55:12 | Deep Dive |
| CVE-2022-41635 | WordPress Advanced Shipment Tracking for WooCommerce Plugin <= 3.5.2 is vulnerable to Cross Site Request Forgery (CSRF) | Zorem | Advanced Shipment Tracking for WooCommerce | Medium | 4.3 | 2023-05-25 08:59:09 | Deep Dive |
| CVE-2022-46812 | WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF) | VillaTheme | Thank You Page Customizer for WooCommerce – Increase Your Sales | Medium | 4.3 | 2023-05-25 08:48:58 | Deep Dive |
| CVE-2022-47164 | WordPress Event Manager for WooCommerce Plugin <= 3.7.7 is vulnerable to Cross Site Request Forgery (CSRF) | MagePeople Team | Event Manager and Tickets Selling Plugin for WooCommerce | Medium | 4.3 | 2023-05-25 08:27:25 | Deep Dive |
| CVE-2022-46794 | WordPress WooCommerce Weight Based Shipping Plugin <= 5.4.1 is vulnerable to Cross Site Request Forgery (CSRF) | weightbasedshipping.com | WooCommerce Weight Based Shipping | Medium | 4.3 | 2023-05-24 16:00:07 | Deep Dive |
| CVE-2022-45376 | WordPress Side Cart Woocommerce (Ajax) Plugin < 2.1 is vulnerable to Cross Site Request Forgery (CSRF) | XootiX | Side Cart Woocommerce (Ajax) | Medium | 4.3 | 2023-05-22 09:22:46 | Deep Dive |
| CVE-2023-2276 | WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.10.7 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Password Change | wclovers | WCFM Membership – WooCommerce Memberships for Multivendor Marketplace | Critical | 9.8 | 2023-05-20 03:35:57 | Deep Dive |
| CVE-2023-23667 | WordPress Brands for WooCommerce Plugin <= 3.7.0.6 is vulnerable to Cross Site Scripting (XSS) | BeRocket | Brands for WooCommerce | Medium | 6.5 | 2023-05-18 10:21:15 | Deep Dive |
| CVE-2023-2706 | OTP Login Woocommerce & Gravity Forms <= 2.2 - Authentication Bypass to Privilege Escalation | xootix | OTP Login & Register Woocommerce | High | 8.1 | 2023-05-17 01:58:49 | Deep Dive |
| CVE-2023-1839 | Product Addons & Fields for WooCommerce < 32.0.6 - Admin+ Stored Cross-Site Scripting | Unknown | Product Addons & Fields for WooCommerce | 中危 | - | 2023-05-15 12:15:46 | Deep Dive |
| CVE-2023-2179 | WooCommerce Order Status Change Notifier <= 1.1.0 - Subscriber+ Arbitrary Order Status Update | Unknown | WooCommerce Order Status Change Notifier | 中危 | - | 2023-05-15 12:15:36 | Deep Dive |
| CVE-2022-46858 | WordPress Product Specifications for Woocommerce Plugin <= 0.6.0 is vulnerable to Cross Site Scripting (XSS) | Amin A.Rezapour | Product Specifications for Woocommerce | High | 7.1 | 2023-05-09 11:40:30 | Deep Dive |
| CVE-2022-46864 | WordPress Woocommerce Custom Checkout Fields Editor With Drag & Drop Plugin <= 0.1 is vulnerable to Cross Site Scripting (XSS) | Umair Saleem | Woocommerce Custom Checkout Fields Editor With Drag & Drop | High | 7.1 | 2023-05-09 11:33:38 | Deep Dive |
| CVE-2022-46822 | WordPress WooCommerce JazzCash Gateway Plugin Plugin <= 2.0 is vulnerable to Cross Site Scripting (XSS) | JC Development Team | WooCommerce JazzCash Gateway Plugin | High | 7.1 | 2023-05-09 11:12:09 | Deep Dive |
| CVE-2023-22710 | WordPress Return and Warranty Management System for WooCommerce Plugin <= 1.2.3 is vulnerable to Cross Site Scripting (XSS) | chilidevs | Return and Warranty Management System for WooCommerce | High | 7.1 | 2023-05-08 22:05:03 | Deep Dive |
| CVE-2023-0537 | Product Slider For WooCommerce Lite <= 1.1.7 - Contributor+ Stored XSS | Unknown | Product Slider For WooCommerce Lite | 中危 | - | 2023-05-08 13:58:23 | Deep Dive |
| CVE-2022-4118 | Bitcoin / AltCoin Payment Gateway <= 1.7.1 - Unauthenticated SQLi | Unknown | Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop | 超危 | - | 2023-05-08 13:58:20 | Deep Dive |
| CVE-2023-0948 | Japanized For WooCommerce < 2.5.8 - Reflected XSS | Unknown | Japanized For WooCommerce | 中危 | - | 2023-05-08 13:58:04 | Deep Dive |