| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-2537 | WooCommerce PDF Invoices & Packing Slips < 3.0.1 - Reflected Cross-Site Scripting | Unknown | WooCommerce PDF Invoices & Packing Slips | 中危 | - | 2022-08-29 17:15:36 | Deep Dive |
| CVE-2022-2556 | MailChimp for Woocommerce < 2.7.2 - Admin+ SSRF | Unknown | Mailchimp for WooCommerce | 低危 | - | 2022-08-29 17:15:36 | Deep Dive |
| CVE-2022-2267 | MailChimp for Woocommerce < 2.7.1 - Subscriber+ SSRF | Unknown | Mailchimp for WooCommerce | 中危 | - | 2022-08-29 17:15:35 | Deep Dive |
| CVE-2022-36379 | WordPress ЮKassa для WooCommerce plugin <= 2.3.0 - Cross-Site Request Forgery (CSRF) leading to plugin settings update | YooMoney | ЮKassa для WooCommerce (WordPress plugin) | High | 8.8 | 2022-08-23 15:47:42 | Deep Dive |
| CVE-2022-34868 | WordPress ЮKassa для WooCommerce plugin <= 2.3.0 - Authenticated Arbitrary Settings Update vulnerability | YooMoney | ЮKassa для WooCommerce (WordPress plugin) | High | 8.8 | 2022-08-23 15:46:08 | Deep Dive |
| CVE-2022-2555 | Yotpo Reviews for WooCommerce <= 2.0.4 - Arbitrary Settings Update via CSRF | Unknown | Yotpo Reviews for WooCommerce (Unofficial) | 中危 | - | 2022-08-22 15:04:12 | Deep Dive |
| CVE-2022-2389 | Automations By Autonami < 2.1.2 - Subscriber+ Automation Creation | Unknown | Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami | 中危 | - | 2022-08-22 15:02:49 | Deep Dive |
| CVE-2022-2382 | Product Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options Deletion | Unknown | Product Slider for WooCommerce | 中危 | - | 2022-08-22 15:02:20 | Deep Dive |
| CVE-2022-36284 | WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email change | StoreApps | Affiliate For WooCommerce (WordPress plugin) | Medium | 6.4 | 2022-08-05 15:08:52 | Deep Dive |
| CVE-2022-25649 | WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Multiple Improper Access Control vulnerabilities | StoreApps | Affiliate For WooCommerce (WordPress plugin) | Medium | 5.0 | 2022-08-05 15:07:53 | Deep Dive |
| CVE-2022-33901 | WordPress MultiSafepay plugin for WooCommerce plugin <= 4.13.1 - Unauthenticated Arbitrary File Read vulnerability | MultiSafepay | MultiSafepay plugin for WooCommerce (WordPress plugin) | Medium | 5.3 | 2022-07-22 16:52:53 | Deep Dive |
| CVE-2022-30998 | WordPress Homepage Product Organizer for WooCommerce plugin <= 1.1 - Multiple Authenticated SQL Injection (SQLi) vulnerabilities | WooPlugins.co | Homepage Product Organizer for WooCommerce (WordPress plugin) | Critical | 9.1 | 2022-07-22 16:48:27 | Deep Dive |
| CVE-2022-28666 | WordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerability | YIKES Inc. | Custom Product Tabs for WooCommerce (WordPress plugin) | Medium | 5.3 | 2022-07-21 16:59:23 | Deep Dive |
| CVE-2022-2099 | WooCommerce < 6.6.0 - Admin+ Stored HTML Injection | Unknown | WooCommerce | 中危 | - | 2022-07-17 10:35:52 | Deep Dive |
| CVE-2022-2090 | Woo Discount Rules < 2.4.2 - Reflected Cross-Site Scripting | Unknown | Discount Rules for WooCommerce | 中危 | - | 2022-07-17 10:35:45 | Deep Dive |
| CVE-2022-1933 | CDI < 5.1.9 - Reflected Cross-Site-Scripting | Unknown | CDI – Collect and Deliver Interface for Woocommerce | 中危 | - | 2022-07-17 10:35:39 | Deep Dive |
| CVE-2022-2092 | WooCommerce PDF Invoices & Packing Slips < 2.16.0 - Reflected Cross-Site Scripting | Unknown | WooCommerce PDF Invoices & Packing Slips | 中危 | - | 2022-07-11 12:57:25 | Deep Dive |
| CVE-2022-1546 | WooCommerce - Product Importer <= 1.5.2 - Reflected Cross-Site Scripting | Unknown | WooCommerce – Product Importer | 中危 | - | 2022-07-11 12:55:51 | Deep Dive |
| CVE-2022-1057 | Pricing Deals for WooCommerce <= 2.0.2.02 - Unauthenticated SQLi | Unknown | Pricing Deals for WooCommerce | 超危 | - | 2022-07-11 12:55:35 | Deep Dive |
| CVE-2022-1953 | Product Configurator for WooCommerce < 1.2.32 - Unauthenticated Arbitrary File Deletion | Unknown | Product Configurator for WooCommerce | 超危 | - | 2022-06-27 08:58:44 | Deep Dive |