| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Jan 19, 2026, 13:01:55 | ||||
|
SAFE & CERTIFIED
|
Jan 16, 2026, 16:01:44 |
Min 2.9.3
Max 2.9.3
|
WP Multibyte Patch v2.9.3 has successfully passed the CleanTalk Plugin Security Certification (PSC-2025-64598). This certification confirms that the plugin’s codebase was reviewed and validated against a broad range of high-impact vulnerability classes, ensuring it can be used confidently in production environments. | |
|
vulnerable
|
Jan 11, 2026, 12:01:53 |
Min -
Max 1.1.7
|
The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its settings, which could allow any authenticated users to update them. | |
|
vulnerable
|
Jan 11, 2026, 12:01:21 |
Min -
Max 1.0.7
|
Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: from n/a through 1.0.7. | |
|
vulnerable
|
Jan 11, 2026, 12:01:18 |
Min -
Max 1.5.11
|
Missing Authorization vulnerability in Bit Apps Bit Assist bit-assist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bit Assist: from n/a through <= 1.5.11. | |
|
Free Follow-Up Emails & Marketing Automation for WooCommerce – ShopMagic
vulnerable
|
Jan 11, 2026, 12:01:16 |
Min -
Max 4.7.2
|
Missing Authorization vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShopMagic: from n/a through <= 4.7.2. | |
|
vulnerable
|
Jan 11, 2026, 12:01:16 |
Min -
Max 3.9.0
|
Missing Authorization vulnerability in SALESmanago SALESmanago salesmanago allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SALESmanago: from n/a through <= 3.9.0. | |
|
WC Builder – WooCommerce Page Builder for WPBakery
vulnerable
|
Jan 11, 2026, 12:01:15 |
Min -
Max 1.2.1
|
The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'heading_color' parameter (and multiple other styling parameters) of the `wpbforwpbakery_product_additional_information` shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inject arbitrary web scripts in pages that will exe... | |
|
WC Builder – WooCommerce Page Builder for WPBakery
vulnerable
|
Jan 11, 2026, 12:01:15 |
Min -
Max 1.2.0
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WC Builder wc-builder allows Stored XSS.This issue affects WC Builder: from n/a through <= 1.2.0. | |
|
TempTool [Show Current Template Info]
vulnerable
|
Jan 11, 2026, 11:01:55 |
Min -
Max 1.3.1
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool allows Stored XSS.This issue affects TempTool: from n/a through 1.3.1. | |
|
Campay Woocommerce Payment Gateway
vulnerable
|
Jan 11, 2026, 11:01:10 |
Min -
Max 1.2.2
|
The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly validating that a transaction has occurred through the payment gateway. This makes it possible for unauthenticated attackers to bypass payments and mark orders as successfully completed resulting in a loss of income. | |