Known Vulnerabilities for Order Tip For WooCommerce by Railmedia
Listed below are 10 of the newest known vulnerabilities associated with "Order Tip For WooCommerce" by "Railmedia".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57857 json | The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooComme... | Not Provided | 2026-07-18 | 2026-07-20 |
| CVE-2026-57402 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund ... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-56042 json | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-49110 json | Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-42386 json | Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-15759 json | The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to S... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-14500 json | The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and includ... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-13459 json | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions... | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-13116 json | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in al... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-12973 json | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one... | Not Provided | 2026-07-20 | 2026-07-20 |