SecAlerts
wpswings logo

wpswings

Security Risk Profile

36
/100
low

Security Risk Score

Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 26, 2022 to present

17
Total CVEs
9
Critical+High
1
Exploited
6
Unpatched

Threat Assessment

Avg CVSS
7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
6
Critical/High
Risk Level
36/100
low
⚠️ 1 Active Exploits

Severity Distribution

Critical
6
High
3
Medium
8
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
CSRF
3
2
Malicious File Upload
3
3
SQL Injection
2
4
XSS
2
5
Infoleak
1

Most Affected Products

1. Wpswings Return Refund And Exchange For Woocommerce Wordpress3
2. Wpswings WooCommerce Ultimate Gift Card2
3. Wpswings Ultimate Gift Cards For Woocommerce Wordpress2
4. WooCommerce Wallet System for WooCommerce2
5. Wpswings Wallet System For Woocommerce Wordpress2

Recent Vulnerabilities

See more →
CVE-2025-64267
CVSS 4.3medium

WordPress WooCommerce Ultimate Points And Rewards plugin <= 2.10.2 - Sensitive Data Exposure vulnerability

11/13/2025🔧 No Patch
CVE-2025-47569
CVSS 9.3critical

WordPress WooCommerce Ultimate Gift Card plugin <= 2.9.6 - SQL Injection vulnerability

9/9/2025🔧 No Patch
CVE-2025-5103
CVSS 4.9EPSS 0%medium

Ultimate Gift Cards for WooCommerce <= 3.1.4 - Authenticated (Administrator+) SQL Injection via wps_wgm_save_post Function

6/3/2025
CVE-2024-13724
CVSS 4.3medium

Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization

3/4/2025
CVE-2024-13682
CVSS 4.3medium

Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery

3/4/2025
CVE-2024-8425
CVSS 9.8critical

WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload

2/28/2025🔧 No Patch
CVE-2024-13692
CVSS 5.4medium

Return Refund and Exchange For WooCommerce <= 4.4.5 - Authenticated (Subscriber+) Insecure Direct Object Reference

2/14/2025
CVE-2024-13641
CVSS 7.5high

Return Refund and Exchange For WooCommerce <= 4.4.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

2/14/2025
CVE-2024-53740
CVSS 7.1high

WordPress WooCommerce Ultimate Gift Card plugin < 2.9.1 - Reflected Cross Site Scripting (XSS) vulnerability

12/2/2024
CVE-2023-27608
CVSS 9.8critical

WordPress Points and Rewards for WooCommerce plugin <= 1.5.0 - Broken Access Control vulnerability

3/25/2024

Monitor wpswings in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.