| CVE-2022-2575 | WBW Currency Switcher for WooCommerce < 1.6.6 - Admin+ Stored XSS | Unknown | WBW Currency Switcher for WooCommerce | 中危 | - | 2022-09-16 08:40:29 | Deep Dive |
| CVE-2022-35275 | WordPress Advanced Order Export For WooCommerce plugin <= 3.3.1 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability | AlgolPlus | Advanced Order Export For WooCommerce (WordPress plugin) | Medium | 4.8 | 2022-09-09 14:39:56 | Deep Dive |
| CVE-2022-2518 | Stockists Manager for Woocommerce <= 1.0.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting | dholovnia | Stockists Manager for Woocommerce | High | 8.8 | 2022-09-06 17:18:58 | Deep Dive |
| CVE-2022-2429 | Ultimate SMS Notifications for WooCommerce <= 1.4.1 - CSV Injection | homescript | Ultimate SMS Notifications for WooCommerce | Medium | 6.5 | 2022-09-06 17:18:56 | Deep Dive |
| CVE-2022-2657 | Multivendor Marketplace Solution for WooCommerce < 3.8.12 - Unauthorised AJAX Calls | Unknown | Multivendor Marketplace Solution for WooCommerce – WC Marketplace | 中危 | - | 2022-09-05 12:35:22 | Deep Dive |
| CVE-2022-2537 | WooCommerce PDF Invoices & Packing Slips < 3.0.1 - Reflected Cross-Site Scripting | Unknown | WooCommerce PDF Invoices & Packing Slips | 中危 | - | 2022-08-29 17:15:36 | Deep Dive |
| CVE-2022-2556 | MailChimp for Woocommerce < 2.7.2 - Admin+ SSRF | Unknown | Mailchimp for WooCommerce | 低危 | - | 2022-08-29 17:15:36 | Deep Dive |
| CVE-2022-2267 | MailChimp for Woocommerce < 2.7.1 - Subscriber+ SSRF | Unknown | Mailchimp for WooCommerce | 中危 | - | 2022-08-29 17:15:35 | Deep Dive |
| CVE-2022-36379 | WordPress ЮKassa для WooCommerce plugin <= 2.3.0 - Cross-Site Request Forgery (CSRF) leading to plugin settings update | YooMoney | ЮKassa для WooCommerce (WordPress plugin) | High | 8.8 | 2022-08-23 15:47:42 | Deep Dive |
| CVE-2022-34868 | WordPress ЮKassa для WooCommerce plugin <= 2.3.0 - Authenticated Arbitrary Settings Update vulnerability | YooMoney | ЮKassa для WooCommerce (WordPress plugin) | High | 8.8 | 2022-08-23 15:46:08 | Deep Dive |
| CVE-2022-2555 | Yotpo Reviews for WooCommerce <= 2.0.4 - Arbitrary Settings Update via CSRF | Unknown | Yotpo Reviews for WooCommerce (Unofficial) | 中危 | - | 2022-08-22 15:04:12 | Deep Dive |
| CVE-2022-2389 | Automations By Autonami < 2.1.2 - Subscriber+ Automation Creation | Unknown | Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami | 中危 | - | 2022-08-22 15:02:49 | Deep Dive |
| CVE-2022-2382 | Product Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options Deletion | Unknown | Product Slider for WooCommerce | 中危 | - | 2022-08-22 15:02:20 | Deep Dive |
| CVE-2022-36284 | WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email change | StoreApps | Affiliate For WooCommerce (WordPress plugin) | Medium | 6.4 | 2022-08-05 15:08:52 | Deep Dive |
| CVE-2022-25649 | WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Multiple Improper Access Control vulnerabilities | StoreApps | Affiliate For WooCommerce (WordPress plugin) | Medium | 5.0 | 2022-08-05 15:07:53 | Deep Dive |
| CVE-2022-33901 | WordPress MultiSafepay plugin for WooCommerce plugin <= 4.13.1 - Unauthenticated Arbitrary File Read vulnerability | MultiSafepay | MultiSafepay plugin for WooCommerce (WordPress plugin) | Medium | 5.3 | 2022-07-22 16:52:53 | Deep Dive |
| CVE-2022-30998 | WordPress Homepage Product Organizer for WooCommerce plugin <= 1.1 - Multiple Authenticated SQL Injection (SQLi) vulnerabilities | WooPlugins.co | Homepage Product Organizer for WooCommerce (WordPress plugin) | Critical | 9.1 | 2022-07-22 16:48:27 | Deep Dive |
| CVE-2022-28666 | WordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerability | YIKES Inc. | Custom Product Tabs for WooCommerce (WordPress plugin) | Medium | 5.3 | 2022-07-21 16:59:23 | Deep Dive |
| CVE-2022-2099 | WooCommerce < 6.6.0 - Admin+ Stored HTML Injection | Unknown | WooCommerce | 中危 | - | 2022-07-17 10:35:52 | Deep Dive |
| CVE-2022-2090 | Woo Discount Rules < 2.4.2 - Reflected Cross-Site Scripting | Unknown | Discount Rules for WooCommerce | 中危 | - | 2022-07-17 10:35:45 | Deep Dive |