All 5 CVE vulnerabilities found in Hippoo Mobile App for WooCommerce, with AI-generated Chinese analysis, references, and POCs.
Vendor: hippooo
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-49065 | WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.5 - Broken Access Control vulnerability CWE-862 | 8.2 | High | 2026-06-15 |
| CVE-2026-49060 | WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability CWE-266 | 9.8 | Critical | 2026-06-11 |
| CVE-2026-10580 | Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API CWE-285 | 9.8 | Critical | 2026-06-05 |
| CVE-2025-12655 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Missing Authorization to Unauthenticated Limited File Write CWE-862 | 5.3 | Medium | 2025-12-12 |
| CVE-2025-13339 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read CWE-22 | 7.5 | High | 2025-12-10 |
All 5 known CVE vulnerabilities affecting Hippoo Mobile App for WooCommerce with full Chinese analysis, references, and POCs where available.