Vulnerabilities in WPFactory
48 resultsCVE-2024-34370HIGHWordPress EAN for WooCommerce plugin <= 4.8.9 - Arbitrary Option Update to Privilege Escalation vulnerabilityEPSS 1.1%CVE-2023-23868MEDIUMWordPress Cost of Goods for WooCommerce plugin <= 2.8.6 - Broken Access Control vulnerabilityEPSS 0.6%CVE-2025-31553CRITICALWordPress Advanced WooCommerce Product Sales Reporting plugin <= 4.1.1 - SQL Injection vulnerabilityEPSS 0.5%CVE-2023-47547HIGHWordPress Products, Order & Customers Export for WooCommerce Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2025-30781MEDIUMWordPress Scheduled & Automatic Order Status Controller for WooCommerce plugin <= 3.7.1 - Open Redirection VulnerabilityEPSS 0.4%CVE-2024-49305CRITICALWordPress Customer Email Verification for WooCommerce plugin <= 2.8.10 - SQL Injection vulnerabilityEPSS 0.4%CVE-2024-31276MEDIUMWordPress Products, Order & Customers Export for WooCommerce plugin <= 2.0.8 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-31848MEDIUMWordPress WordPress Adverts Plugin plugin <= 1.4 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-23977HIGHWordPress Helpdesk Support Ticket System for WooCommerce plugin <= 2.1.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2023-36689HIGHWordPress WPFactory Helper Plugin <= 1.5.2 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2025-49887CRITICALWordPress Product XML Feed Manager for WooCommerce Plugin <= 2.9.3 - Remote Code Execution (RCE) VulnerabilityEPSS 0.3%CVE-2023-51399MEDIUMWordPress Back Button Widget Plugin <= 1.6.3 is vulnerable to Cross Site Scripting (XSS)EPSS 0.3%CVE-2025-30959MEDIUMWordPress Product XML Feed Manager for WooCommerce <= 2.9.2 - Broken Access Control VulnerabilityEPSS 0.3%CVE-2025-39601CRITICALWordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerabilityEPSS 0.3%CVE-2024-43127HIGHWordPress Products, Order & Customers Export for WooCommerce plugin <= 2.0.11 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2026-24993CRITICALWordPress Advanced WooCommerce Product Sales Reporting plugin <= 4.1.3 - SQL Injection vulnerabilityEPSS 0.3%CVE-2024-56228HIGHWordPress Wishlist for WooCommerce: Multi Wishlists Per Customer plugin <= 3.1.2 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2024-54209HIGHWordPress Awesome Shortcodes plugin <= 1.7.2 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-49319MEDIUMWordPress Wishlist for WooCommerce <= 3.2.3 - Broken Access Control VulnerabilityEPSS 0.3%CVE-2025-32552HIGHWordPress MSRP (RRP) Pricing for WooCommerce Plugin <= 1.8.1 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%