SecAlerts
v

vanquish

Security Risk Profile

49
/100
medium

Security Risk Score

Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 5, 2021 to present

18
Total CVEs
12
Critical+High
1
Exploited
12
Unpatched

Threat Assessment

Avg CVSS
8.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
12
Critical/High
Risk Level
49/100
medium
⚠️ 1 Active Exploits

Severity Distribution

Critical
5
High
7
Medium
6
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Path Traversal
5
2
CSRF
4
3
Malicious File Upload
3
4
XSS
2
5
Infoleak
1

Most Affected Products

1. WooCommerce Customers Manager7
2. Vanquish Woocommerce Customers Manager Wordpress7
3. WooCommerce Support Ticket System4
4. Vanquish Woocommerce Support Ticket System Wordpress4
5. Vanquish WooCommerce Orders & Customers Exporter2

Recent Vulnerabilities

See more →
CVE-2026-32522
CVSS 8.6high

WordPress WooCommerce Support Ticket System plugin < 18.5 - Arbitrary File Deletion vulnerability

Mar 25, 2026🔧 No Patch
CVE-2025-53424
CVSS 6.5medium

WordPress WooCommerce Orders & Customers Exporter plugin <= 5.4 - Broken Access Control vulnerability

Oct 22, 2025🔧 No Patch
CVE-2025-48331
CVSS 7.5EPSS 0%high

WordPress WooCommerce Orders & Customers Exporter <= 5.0 - Sensitive Data Exposure Vulnerability

May 30, 2025🔧 No Patch
CVE-2024-13775
CVSS 5.4medium

WooCommerce Support Ticket System <= 17.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Information Exposure

Feb 1, 2025🔧 No Patch
CVE-2024-13343
CVSS 8.8high

WooCommerce Customers Manager <= 31.3 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

Feb 1, 2025🔧 No Patch
CVE-2024-11150
CVSS 9.8critical

WordPress User Extra Fields <= 16.6 - Unauthenticated Arbitrary File Deletion

Nov 13, 2024🔧 No Patch
CVE-2024-10800
CVSS 8.8high

WordPress User Extra Fields <= 16.6 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

Nov 13, 2024🔧 No Patch
CVE-2024-10820
CVSS 9.8critical

WooCommerce Upload Files <= 84.3 - Unauthenticated Arbitrary File Upload

Nov 13, 2024🔧 No Patch
CVE-2024-10627
CVSS 9.8critical

WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Upload

Nov 9, 2024🔧 No Patch
CVE-2024-10626
CVSS 8.8high

WooCommerce Support Ticket System <= 17.7 - Authenticated (Subscriber+) Arbitrary File Deletion

Nov 9, 2024🔧 No Patch

Monitor vanquish in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

vanquish Security Vulnerabilities & Risk Score | 18 CVEs | SecAlerts - SecAlerts