| CVE-2020-36696 | Product Input Fields for WooCommerce <= 1.2.6 - Missing Authorization | tychesoftwares | Product Input Fields for WooCommerce | High | 7.5 | 2023-06-07 01:51:10 | Deep Dive |
| CVE-2023-2833 | ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation | reviewx | ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema | High | 8.8 | 2023-06-06 09:33:23 | Deep Dive |
| CVE-2023-2781 | User Email Verification for WooCommerce <= 3.5.0 - Authentication Bypass | sandeepsoni214 | User Email Verification for WooCommerce | High | 8.1 | 2023-06-02 23:37:57 | Deep Dive |
| CVE-2023-2256 | Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting | Unknown | Product Addons & Fields for WooCommerce | 中危 | - | 2023-05-30 07:49:09 | Deep Dive |
| CVE-2022-45372 | WordPress Product Gallery Slider for WooCommerce Plugin <= 2.2.8 is vulnerable to Cross Site Request Forgery (CSRF) | Codeixer | Product Gallery Slider for WooCommerce | Medium | 4.3 | 2023-05-29 00:15:46 | Deep Dive |
| CVE-2023-33332 | WordPress WooCommerce Product Vendors Plugin <= 2.1.76 is vulnerable to Cross Site Scripting (XSS) | WooCommerce | WooCommerce Product Vendors | High | 7.1 | 2023-05-28 18:53:50 | Deep Dive |
| CVE-2023-33319 | WordPress WooCommerce Follow-Up Emails Plugin <= 4.9.40 is vulnerable to Cross Site Scripting (XSS) | WooCommerce | WooCommerce Follow-Up Emails (AutomateWoo) | High | 7.1 | 2023-05-28 18:07:45 | Deep Dive |
| CVE-2023-33316 | WordPress WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 is vulnerable to Cross Site Request Forgery (CSRF) | WooCommerce | WooCommerce Follow-Up Emails (AutomateWoo) | Medium | 5.4 | 2023-05-28 18:01:01 | Deep Dive |
| CVE-2023-33216 | WordPress WooDiscuz – WooCommerce Comments Plugin <= 2.2.9 is vulnerable to Cross Site Scripting (XSS) | gVectors Team | WooDiscuz – WooCommerce Comments | Medium | 5.9 | 2023-05-28 16:58:52 | Deep Dive |
| CVE-2022-46856 | WordPress Woocommerce Product Designer Plugin <= 4.3.3 is vulnerable to Cross Site Request Forgery (CSRF) | ORION | Woocommerce Products Designer | Medium | 5.4 | 2023-05-25 11:23:58 | Deep Dive |
| CVE-2022-46810 | WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF) | VillaTheme | Thank You Page Customizer for WooCommerce – Increase Your Sales | Medium | 4.3 | 2023-05-25 11:18:45 | Deep Dive |
| CVE-2022-45367 | WordPress Custom Order Numbers for WooCommerce Plugin <= 1.4.0 is vulnerable to Cross Site Request Forgery (CSRF) | Tyche Softwares | Custom Order Numbers for WooCommerce | Medium | 4.3 | 2023-05-25 09:55:12 | Deep Dive |
| CVE-2022-41635 | WordPress Advanced Shipment Tracking for WooCommerce Plugin <= 3.5.2 is vulnerable to Cross Site Request Forgery (CSRF) | Zorem | Advanced Shipment Tracking for WooCommerce | Medium | 4.3 | 2023-05-25 08:59:09 | Deep Dive |
| CVE-2022-46812 | WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF) | VillaTheme | Thank You Page Customizer for WooCommerce – Increase Your Sales | Medium | 4.3 | 2023-05-25 08:48:58 | Deep Dive |
| CVE-2022-47164 | WordPress Event Manager for WooCommerce Plugin <= 3.7.7 is vulnerable to Cross Site Request Forgery (CSRF) | MagePeople Team | Event Manager and Tickets Selling Plugin for WooCommerce | Medium | 4.3 | 2023-05-25 08:27:25 | Deep Dive |
| CVE-2022-46794 | WordPress WooCommerce Weight Based Shipping Plugin <= 5.4.1 is vulnerable to Cross Site Request Forgery (CSRF) | weightbasedshipping.com | WooCommerce Weight Based Shipping | Medium | 4.3 | 2023-05-24 16:00:07 | Deep Dive |
| CVE-2022-45376 | WordPress Side Cart Woocommerce (Ajax) Plugin < 2.1 is vulnerable to Cross Site Request Forgery (CSRF) | XootiX | Side Cart Woocommerce (Ajax) | Medium | 4.3 | 2023-05-22 09:22:46 | Deep Dive |
| CVE-2023-2276 | WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.10.7 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Password Change | wclovers | WCFM Membership – WooCommerce Memberships for Multivendor Marketplace | Critical | 9.8 | 2023-05-20 03:35:57 | Deep Dive |
| CVE-2023-23667 | WordPress Brands for WooCommerce Plugin <= 3.7.0.6 is vulnerable to Cross Site Scripting (XSS) | BeRocket | Brands for WooCommerce | Medium | 6.5 | 2023-05-18 10:21:15 | Deep Dive |
| CVE-2023-2706 | OTP Login Woocommerce & Gravity Forms <= 2.2 - Authentication Bypass to Privilege Escalation | xootix | OTP Login & Register Woocommerce | High | 8.1 | 2023-05-17 01:58:49 | Deep Dive |