PoC Archive PoC Archive

tag

Woocommerce

Critical
WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)
CVE-2025-6440· WordPress WooCommerce Dynamic Pricing & Discounts plugin (wc-designer-pro) unpatched
Critical
Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009· Webkul "Medical Prescription Attachment Plugin for WooCommerce" (WordPress plugin) patched
Critical
StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)
CVE-2025-48148· StoreKeeper for WooCommerce (WordPress plugin) unpatched
Critical
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391· PPOM for WooCommerce (woocommerce-product-addon plugin) patched
High
YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
CVE-2026-1937· YayMail – WooCommerce Email Customizer plugin for WordPress unpatched
Critical
WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540)· WooCommerce Wholesale Lead Capture (WWLC) plugin for WordPress unpatched
Not disclosed
WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
CVE-2026-54807· WordPress plugin exposing a custom WooCommerce-style frontend registration form (form fields prefixed tgwcfb_*) unpatched
Critical
Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580· Hippoo Mobile App for WooCommerce (WordPress plugin) unpatched