Filter
AND
-Infinity
0

WordPress WooCommerce Estimate and QuoteWordPress WooCommerce Estimate and Quote plugin <= 1.0.2.5 - Reflected Cross Site Scripting (XSS) vulnerability

7.1
EPSS
0.03%
First published (updated )

WooCommerce DN Shipping by WeightWordPress DN Shipping by Weight for WooCommerce Plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerability

7.1
EPSS
0.03%
First published (updated )

WordPress Product Import Export for WooCommerceProduct Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

7.2
First published (updated )

WordPress Product Import Export for WooCommerceProduct Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

7.6
First published (updated )

WooCommerce Active Products Tables for WooCommerceActive Products Tables for WooCommerce <= 1.0.6.7 - Unauthenticated Arbitrary Filter Call

7.3
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

WebToffee Order Export & Order Import for WooCommerceOrder Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

7.2
First published (updated )

NP Quote Request for WooCommerceNP Quote Request for WooCommerce <= 1.9.179 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure

7.5
First published (updated )

WebToffee Order Export & Order Import for WooCommerceOrder Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

7.6
First published (updated )

WooCommerce Recover Abandoned CartWooCommerce Recover Abandoned Cart <= 24.3.0 - Unauthenticated PHP Object Injection

8.1
First published (updated )

Wpbranch Tabs For WoocommerceTabs for WooCommerce <= 1.0.0 - Authentiated (Shop Manager+) PHP Object Injection in product_has_custom_tabs

7.2
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

WooCommerce Order Attachments for WooCommerceOrder Attachments for WooCommerce <= 2.5.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

7.5
First published (updated )

WordPress Distance Rate Shipping for WooCommerceWordPress Distance Rate Shipping for WooCommerce plugin <= 1.3.4 - SQL Injection vulnerability

8.5
First published (updated )

WooCommerce File Uploads AddonFile Uploads Addon for WooCommerce <= 1.7.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

7.5
First published (updated )

WooCommerce Returns and Warranty RequestsReturn Refund and Exchange For WooCommerce <= 4.4.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

7.5
First published (updated )

Wpfactory Customer Email Verification for WooCommerceCustomer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via Shortcode

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

CURCY WooCommerce Multi Currency - Currency SwitcherCURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function

7.3
First published (updated )

WooCommerce Customers ManagerThe WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to …

8.8
First published (updated )

Wcproducttable Woocommerce Product Table LiteCode Injection

7.3
First published (updated )

MoreConvert MC Woocommerce WishlistWooCommerce Wishlist <= 1.8.7 - Unauthenticated Wishlist Disclosure via download_pdf_file Function

7.5
First published (updated )

WooCommerce Order SearchWordPress WooCommerce Order Search plugin <= 1.1.0 - Reflected Cross Site Scripting (XSS) vulnerability

7.1
EPSS
0.04%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

WooCommerce SMS Alert Order NotificationsSMS Alert Order Notifications – WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

8.8
First published (updated )

Webbuilder143 Custom Product Tabs For WooCommerceCustom Product Tabs For WooCommerce <= 1.2.4 - Authenticated (Shop Manager+) PHP Object Injection

7.2
First published (updated )

WooCommerce Active Products Tables for WooCommerceActive Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.5 - Unauthenticated Arbitrary Shortcode Execution via woot_get_smth

7.3
First published (updated )

WooCommerceWordPress Woocommerce OpenPos plugin <= 6.4.4 - Unauthenticated Sensitive Data Exposure vulnerability

7.5
First published (updated )

WPWebElite WooCommerce Social Login for WordPressWooCommerce - Social Login <= 2.7.3 - Unauthenticated Authentication Bypass

7.3
EPSS
0.05%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

WPWebElite WooCommerce Social Login for WordPressWooCommerce - Social Login <= 2.7.3 - Unauthenticated Privilege Escalation via One-Time Password

7.3
EPSS
0.05%
First published (updated )

WooCommerceWordPress Woocommerce OpenPos plugin <= 6.4.4 - Unauthenticated Arbitrary File Deletion vulnerability

8.6
First published (updated )

WooCommerce One Page CheckoutWordPress WooCommerce One Page Checkout plugin <= 2.3.0 - Local File Inclusion vulnerability

7.6
First published (updated )

WP ERPSQL Injection

7.2
First published (updated )

WP Overnight WooCommerce PDF Invoices & Packing SlipsXSS

7.2
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203