tag
Woocommerce
Critical
WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)
CVE-2025-6440·
WordPress WooCommerce Dynamic Pricing & Discounts plugin (wc-designer-pro)
unpatched
Critical
Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009·
Webkul "Medical Prescription Attachment Plugin for WooCommerce" (WordPress plugin)
patched
Critical
StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)
CVE-2025-48148·
StoreKeeper for WooCommerce (WordPress plugin)
unpatched
Critical
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391·
PPOM for WooCommerce (woocommerce-product-addon plugin)
patched
High
YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
CVE-2026-1937·
YayMail – WooCommerce Email Customizer plugin for WordPress
unpatched
Critical
WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540)·
WooCommerce Wholesale Lead Capture (WWLC) plugin for WordPress
unpatched
Not disclosed
WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
CVE-2026-54807·
WordPress plugin exposing a custom WooCommerce-style frontend registration form (form fields prefixed tgwcfb_*)
unpatched
Critical
Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580·
Hippoo Mobile App for WooCommerce (WordPress plugin)
unpatched