Vendor
CVE-2026-8761: Privilege Escalation in Dokan WordPress Plugin
1 rule 1 TTP 1 CVEAn improper authorization flaw in the Dokan plugin for WordPress allows authenticated attackers with vendor-level access to escalate privileges to administrator via manipulation of the REST API.
Critical Arbitrary File Upload in WordPress Extra Checkout Options Plugin Leads to RCE (CVE-2026-14270)
2 rules 4 TTPs 1 CVEA critical arbitrary file upload vulnerability (CVE-2026-14270) in the Extra Checkout Options plugin for WordPress, affecting versions up to and including 2.3.2, allows low-privileged authenticated users to modify upload allowlists and upload malicious PHP files via an AJAX action, ultimately achieving remote code execution on the server.
CVE-2026-3688: WordPress WCFM Membership Plugin Insecure Direct Object Reference
2 TTPs 1 CVEAuthenticated attackers with vendor-level access can exploit an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-3688) in the WCFM Membership - WooCommerce Memberships for Multivendor Marketplace plugin for WordPress to change any user's role to 'wcfm_vendor' by manipulating membership plans, leading to unauthorized privilege escalation.
WooCommerce Infinite Scroll Plugin Vulnerable to PHP Object Injection (CVE-2025-11993)
2 rules 1 TTP 1 CVEThe WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection (CVE-2025-11993) due to deserialization of untrusted data in the 'import_settings' function, potentially leading to arbitrary code execution if a suitable POP chain is present.
WooCommerce PayPal Payments Plugin Vulnerable to Order Manipulation and Information Disclosure (CVE-2026-9284)
2 rules 1 TTP 1 CVEThe WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on WC-AJAX endpoints, allowing attackers to manipulate order payment flows and exfiltrate sensitive order details (CVE-2026-9284).
Funnel Builder for WooCommerce Checkout Missing Authorization Vulnerability (CVE-2026-47100)
2 rules 1 CVEFunnel Builder for WooCommerce Checkout versions prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and inject malicious JavaScript, impacting checkout page visitors.
WooCommerce CSV Importer Path Traversal File Deletion (CVE-2018-25325)
2 rules 1 TTP 1 CVEWooCommerce CSV Importer 3.3.6 contains a path traversal vulnerability (CVE-2018-25325) that allows registered users to delete arbitrary files by submitting crafted filenames via the delete_export_file AJAX action.
CVE-2026-4094: FOX – Currency Switcher Professional for WooCommerce Plugin Vulnerability
2 rules 1 TTP 1 CVEThe FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss (CVE-2026-4094) due to a missing capability check, allowing authenticated attackers with Contributor-level access or higher to delete the multi-currency configuration.
Woocommerce Custom Product Addons Pro Plugin RCE Vulnerability (CVE-2026-4001)
2 rules 1 TTPThe Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution (RCE) due to insufficient sanitization of user-submitted field values, allowing unauthenticated attackers to execute arbitrary code via crafted WCPA text fields.