Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2023-36513
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions.
Automatewoo
after 5.7.5
HIGH 8.8
CVE-2023-36514
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions.
Shipping Multiple Addresses
after 3.8.5
HIGH 8.8
CVE-2023-35880
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions.
Brands
1.6.50+
HIGH 8.8
CVE-2023-35917
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.
Paypal Payments
after 2.0.4
MEDIUM 6.1
CVE-2023-35918
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Bulk Stock Management plugin <= 2.2.33 versions.
Bulk Stock Management
after 2.2.33
HIGH 7.5
CVE-2023-34000
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.
Stripe Payment Gateway
7.4.1+
MEDIUM 6.1
CVE-2015-10115
A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affect…
Sidebar Manager To Woosidebars Converter
after 1.1.1
MEDIUM 6.1
CVE-2015-10113
A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the fun…
Wooframework Tweaks
1.0.2+
MEDIUM 6.1
CVE-2015-10114
A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the fu…
Woosidebars
1.4.2+
MEDIUM 6.1
CVE-2015-10112
A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_scr…
Wooframework Branding
after 1.0.1
HIGH 8.8
CVE-2023-33316
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions.
Automatewoo
4.9.50+
MEDIUM 6.1
CVE-2023-33319
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions.
Automatewoo
after 4.9.40
MEDIUM 6.5
CVE-2023-2179
The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an A…
Woocommerce Order Status Change Notifier
after 1.1.0
MEDIUM 6.1
CVE-2015-10104
A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some …
Icons For Features
Patch available
MEDIUM 6.1
CVE-2021-24940
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboa…
Persian Woocommerce
after 5.8.0
MEDIUM 6.1
CVE-2021-24938
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to …
Woocommerce Currency Switcher
1.3.7.1+
CRITICAL 9.8
CVE-2021-24212EPSS 8%
The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to u…
Help Scout
2.9.1+
HIGH 8.8
CVE-2020-35627
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary …
Gift Cards
No fix yet
MEDIUM 5.3
CVE-2020-29156
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetc…
Woocommerce
4.7.0+
HIGH 7.5
CVE-2020-11497
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders t…
Nab Transact
No fix yet
MEDIUM 6.1
CVE-2019-18834
Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Bil…
Subscriptions
2.6.3+
HIGH 8.8
CVE-2019-20891
WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scr…
Woocommerce
3.6.5+
MEDIUM 6.1
CVE-2016-10987
The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
Persian Woocommerce Sms
3.3.4+
MEDIUM 5.3
CVE-2019-14978
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 para…
Payu India Payment Gateway
No fix yet
MEDIUM 5.3
CVE-2019-14979
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount param…
Paypal Checkout Payment Gateway
No fix yet
MEDIUM 6.5
CVE-2019-7441EPSS 6%
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parame…
Paypal Checkout Payment Gateway
No fix yet
MEDIUM 6.1
CVE-2019-9168
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
Woocommerce
3.5.5+
HIGH 8.8
CVE-2017-18356
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account th…
Woocommerce
3.2.4+
HIGH 8.1
CVE-2018-20714
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deleti…
Woocommerce
3.4.6+
MEDIUM 6.1
CVE-2015-2329
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script …
Woocommerce
2.3.6+