Known Vulnerabilities for WPC Order Tip For WooCommerce by Unknown
Listed below are 10 of the newest known vulnerabilities associated with "WPC Order Tip For WooCommerce" by "Unknown".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65559 json | Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-57857 json | The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooComme... | Not Provided | 2026-07-18 | 2026-07-20 |
| CVE-2026-57402 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund ... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-56042 json | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-49110 json | Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-42386 json | Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-18603 json | The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or owner... | Not Provided | 2026-08-09 | 2026-08-09 |
| CVE-2026-18357 json | The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its ... | Not Provided | 2026-08-09 | 2026-08-09 |
| CVE-2026-18059 json | The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposu... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-16981 json | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capabilit... | Not Provided | 2026-08-05 | 2026-08-06 |