Vulnerabilities in WP Swings
30 resultsVexday analysis
WP Swings registra 30 CVEs conhecidas sem exploração ativa em campo, mas 9 divulgações recentes (últimos 90 dias) indicam descobertas contínuas. A fraqueza dominante é falta de autorização (CWE-862), presente em apenas 4 críticas, sugerindo risco moderado e predominantemente em controles de acesso.
CVE-2024-8425CRITICALWooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File UploadEPSS 4.0%CVE-2024-11423HIGHUltimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money GlitchEPSS 0.8%CVE-2024-25100CRITICALWordPress Coupon Referral Program plugin < 1.8.4 - Unauthenticated PHP Object Injection vulnerabilityEPSS 0.8%CVE-2025-6222CRITICALWooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet <= 3.2.6 - Unauthenticated Arbitrary File UploadEPSS 0.6%CVE-2023-52190HIGHWordPress Coupon Referral Program Plugin <= 1.7.2 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2023-27608MEDIUMWordPress Points and Rewards for WooCommerce plugin <= 1.5.0 - Broken Access Control vulnerabilityEPSS 0.5%CVE-2026-24372HIGHWordPress Subscriptions for WooCommerce plugin <= 1.8.10 - Bypass Vulnerability vulnerabilityEPSS 0.5%CVE-2024-38699HIGHWordPress Wallet System for WooCommerce plugin <= 2.5.13 - Sensitive Data Exposure via Exported File vulnerabilityEPSS 0.4%CVE-2023-27607MEDIUMWordPress Points and Rewards for WooCommerce plugin <= 1.5.0 - Settings Change vulnerabilityEPSS 0.4%CVE-2026-57709HIGHWordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2025-54692HIGHWordPress Membership For WooCommerce Plugin <= 2.9.0 - Broken Access Control VulnerabilityEPSS 0.4%CVE-2025-67909HIGHWordPress Membership For WooCommerce plugin <= 3.0.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2025-39579MEDIUMWordPress Membership For WooCommerce plugin <= 2.8.0 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.3%CVE-2025-49265HIGHWordPress Membership For WooCommerce plugin <= 2.8.1 - Broken Access Control VulnerabilityEPSS 0.3%CVE-2026-45444CRITICALWordPress Gift Cards For WooCommerce Pro plugin <= 4.2.6 - Arbitrary File Upload vulnerabilityEPSS 0.3%CVE-2025-32530HIGHWordPress Wallet System for WooCommerce plugin <= 2.6.8 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2026-57332HIGHWordPress Wallet System for WooCommerce plugin <= 2.7.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-34898HIGHWordPress Event Tickets Manager for WooCommerce plugin <= 1.5.3 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-58978MEDIUMWordPress PDF Generator for WordPress Plugin <= 1.5.4 - Broken Access Control VulnerabilityEPSS 0.2%CVE-2026-56061HIGHWordPress Subscriptions for WooCommerce plugin <= 1.9.5 - Broken Access Control vulnerabilityEPSS 0.2%