Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-5062 The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, an… Woocommerce 9.3.4 / 9.4.3+ Fix from $1,6002025-05-22 MEDIUM 6.1 CVE-2024-9944 The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not prope… Woocommerce 9.1.0+ Fix from $1,6002024-10-15 CRITICAL 9.8 CVE-2023-35049 Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a… Stripe Payment Gateway 7.4.1+ Fix from $2,3002024-06-19 MEDIUM 6.5 CVE-2023-51495 Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7. Returns And Warranty Requests 2.3.0+ Fix from $1,6002024-06-14 MEDIUM 5.4 CVE-2023-51497 Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a… Shipping Multiple Addresses 3.8.10+ Fix from $1,6002024-06-14 MEDIUM 5.3 CVE-2023-51496 Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7. Returns And Warranty Requests 2.3.0+ Fix from $1,6002024-06-14 MEDIUM 5.4 CVE-2024-37297 WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. … Woocommerce 8.8.5 / 8.9.3+ Fix from $1,6002024-06-12 MEDIUM 5.3 CVE-2023-34003 Missing Authorization vulnerability in Woo WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.1.51. Box Office 1.1.52+ Fix from $1,6002024-06-09 CRITICAL 9.8 CVE-2023-51494 Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1. Product Vendors 2.2.2+ Fix from $2,3002024-06-09 HIGH 8.8 CVE-2023-44999 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gatew… Stripe Payment Gateway after 7.6.0 Fix from $1,9502024-03-27 HIGH 8.8 CVE-2024-24799 Missing Authorization vulnerability in WooCommerce WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.2.2. Box Office 1.2.3+ Fix from $1,9502024-03-26 MEDIUM 6.1 CVE-2024-27193 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PayU India PayU India payu-india allows DOM-Bas… Payu India Payment Gateway after 3.8.2 Fix from $1,6002024-03-15 HIGH 8.8 CVE-2023-52222 Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2. Woocommerce after 8.2.2 Fix from $1,9502024-01-08 HIGH 7.2 CVE-2023-32795 Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from n/a through 6.1.3. Product Addons after 6.1.3 Fix from $1,9502023-12-28 MEDIUM 6.5 CVE-2023-32799 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addres… Shipping Multiple Addresses after 3.8.3 Fix from $1,6002023-12-21 HIGH 8.8 CVE-2023-33318 Unrestricted Upload of File with Dangerous Type vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.40. Automatewoo after 4.9.40 Fix from $1,9502023-12-20 HIGH 8.1 CVE-2023-33330 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This issue affects Auto… Automatewoo 4.9.51+ Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-32744 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Product Recommendations plugin <= 2.3.0 versions. Product Recommendations 2.3.0+ Fix from $1,9502023-11-09 HIGH 8.8 CVE-2023-32745 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.1 versions. Automatewoo after 5.7.1 Fix from $1,9502023-11-09 HIGH 8.8 CVE-2023-32794 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Product Add-Ons plugin <= 6.1.3 versions. Product Addons after 6.1.3 Fix from $1,9502023-11-09 MEDIUM 5.4 CVE-2023-34004 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Box Office plugin <= 1.1.50 versions. Woocommerce Box Office after 1.1.50 Fix from $1,6002023-08-30 MEDIUM 6.1 CVE-2023-33317 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Returns and Warranty Requests plugin <= 2.1.6 versions. Returns And Warranty Requests after 2.1.6 Fix from $1,6002023-08-30 MEDIUM 6.1 CVE-2023-32801 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Composite Products plugin <= 8.7.5 versions. Composite Products after 8.7.5 Fix from $1,6002023-08-30 MEDIUM 6.1 CVE-2023-32802 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <= 1.9.0 versions. Woocommerce Pre Orders after 1.9.0 Fix from $1,6002023-08-30 MEDIUM 5.4 CVE-2023-32793 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <= 2.0.0 versions. Woocommerce Pre Orders after 2.0.0 Fix from $1,6002023-08-30 MEDIUM 5.4 CVE-2023-32746 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.45 versions. Woocommerce Brands after 1.6.45 Fix from $1,6002023-08-30 MEDIUM 6.1 CVE-2023-37873 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions. Shipping Multiple Addresses after 3.8.5 Fix from $1,6002023-08-05 MEDIUM 6.5 CVE-2023-3507 The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logge… Woocommerce Pre Orders 2.0.3+ Fix from $1,6002023-07-31 MEDIUM 6.5 CVE-2023-3508 The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make… Woocommerce Pre Orders 2.0.3+ Fix from $1,6002023-07-31 HIGH 8.8 CVE-2023-36511 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Order Barcodes plugin <= 1.6.4 versions. Woocommerce Order Barcodes after 1.6.4 Fix from $1,9502023-07-17