Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Acowebs — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting Acowebs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Acowebs develops WordPress plugins for e-commerce and form management, with 11 CVEs recorded. Historically, vulnerabilities have included stored cross-site scripting (XSS), remote code execution (RCE), and privilege escalation, often stemming from insufficient input validation and improper access controls. Notable security characteristics include frequent updates to address flaws, though some vulnerabilities remained unpatched for extended periods. No major public security incidents have been documented, though the consistent pattern of vulnerabilities suggests ongoing security challenges in their plugin development lifecycle.

CVE ID Title CVSS Severity Published
CVE-2026-66475 WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability — Checkout Field Editor for WooCommerce &#8211; Checkout Manager CWE-79 5.9 Medium 2026-07-27
CVE-2026-59556 WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.11 - Cross Site Scripting (XSS) vulnerability — Dynamic Pricing With Discount Rules for WooCommerce CWE-79 7.1 High 2026-07-27
CVE-2026-4001 Woocommerce Custom Product Addons Pro <= 5.4.1 - Unauthenticated Remote Code Execution via Custom Pricing Formula — Woocommerce Custom Product Addons Pro CWE-95 9.8 Critical 2026-03-23
CVE-2026-2296 Product Addons for Woocommerce – Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter — Product Addons for Woocommerce – Product Options with Custom Fields CWE-94 7.2 High 2026-02-18
CVE-2025-12087 Wishlist and Save for later for Woocommerce <= 1.1.22 - Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion — Wishlist and Save for later for Woocommerce CWE-639 4.3 Medium 2025-11-12
CVE-2025-47588 WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.9 - Arbitrary Code Execution vulnerability — Dynamic Pricing With Discount Rules for WooCommerce CWE-94 9.1 Critical 2025-11-06
CVE-2025-62008 WordPress Product Table For WooCommerce plugin <= 1.2.4 - PHP Object Injection vulnerability — Product Table For WooCommerce CWE-502 8.8 High 2025-10-22
CVE-2025-47544 WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.8 - SQL Injection Vulnerability — Dynamic Pricing With Discount Rules for WooCommerce CWE-89 7.6 High 2025-05-07
CVE-2025-22638 WordPress Product Table For WooCommerce Plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability — Product Table For WooCommerce CWE-79 6.5 Medium 2025-03-27
CVE-2024-53817 WordPress Acowebs Product Labels For Woocommerce plugin <= 1.5.8 - SQL Injection vulnerability — Product Labels For Woocommerce CWE-89 7.6 High 2024-12-06
CVE-2024-30230 WordPress PDF Invoices and Packing Slips For WooCommerce plugin <= 1.3.7 - PHP Object Injection vulnerability — PDF Invoices and Packing Slips For WooCommerce CWE-502 8.2 High 2024-03-28
CVE-2024-1773 PDF Invoices and Packing Slips For WooCommerce <= 1.3.7 - Authenticated (Subscriber+) PHP Object Injection — PDF Invoices and Packing Slips For WooCommerce CWE-502 8.8 High 2024-03-07
CVE-2024-24886 WordPress Product Labels For Woocommerce Plugin <= 1.5.3 is vulnerable to Cross Site Scripting (XSS) — Product Labels For Woocommerce (Sale Badges) CWE-79 5.9 Medium 2024-02-08

This page lists every published CVE security advisory associated with Acowebs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.