{"sector":{"id":"ecommerce","name":"E-commerce & Retail","sector":"retail","description":"Online merchants, marketplaces and headless commerce platforms. Focus on\ncart/checkout flows, payment integrations and customer data.","visibility":"public"},"top_24h":[{"id":"8926f54b-4152-4d98-8191-461477dcb84f","threat_type":"cve","title":"The ShopEngine Elementor WooCommerce Builder Addon  WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, a","summary":"The ShopEngine Elementor WooCommerce Builder Addon  WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T06:17:38.230000Z","last_modified_at":"2026-08-13T15:31:46.109948Z","external_id":"CVE-2026-19088","description":"The ShopEngine Elementor WooCommerce Builder Addon  WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.","affected_products":[],"references":["https://wpscan.com/vulnerability/f58066e9-8066-43bc-8778-7ded279e8ee2/"],"sources":["nvd"],"score":75.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":true,"matched":["checkout"],"points":25},"cwe_match":{"hit":true,"matched":["CWE-352"],"points":20},"cvss_threshold":{"hit":false,"threshold":7.0,"cvss_score":5.4,"points":0},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":75,"final_score":75.0},"calculated_at":"2026-08-13T15:31:55.358847Z"},{"id":"d534ae26-7afb-4ad4-83b7-98dc90f0ff4c","threat_type":"cve","title":"Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart &lt;","summary":"Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart &lt;= 2.1.1 versions.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:07.960000Z","last_modified_at":"2026-08-13T14:30:48.292176Z","external_id":"CVE-2026-66466","description":"Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart &lt;= 2.1.1 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/storegrowth-sales-booster/vulnerability/wordpress-storegrowth-smart-sales-booster-for-woocommerce-bogo-upsells-direct-checkout-quick-view-side-cart-plugin-2-1-1-broken-access-control-vulnerability?_s_id=cve"],"sources":["nvd"],"score":70.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":true,"matched":["checkout"],"points":25},"cwe_match":{"hit":false,"matched":[],"points":0},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.5,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":70,"final_score":70.0},"calculated_at":"2026-08-13T14:30:53.247409Z"},{"id":"acfc00f8-889e-4890-a046-754033e51762","threat_type":"cve","title":"Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) &lt;= 1.0.7 versions.","summary":"Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) &lt;= 1.0.7 versions.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:05.120000Z","last_modified_at":"2026-08-13T14:30:46.983031Z","external_id":"CVE-2026-66431","description":"Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) &lt;= 1.0.7 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/clink-gateway-for-woocommerce/vulnerability/wordpress-bitcoin-lightning-payment-gateway-for-woocommerce-via-clink-plugin-1-0-7-broken-access-control-vulnerability?_s_id=cve"],"sources":["nvd"],"score":70.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":true,"matched":["payment gateway"],"points":25},"cwe_match":{"hit":false,"matched":[],"points":0},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.5,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":70,"final_score":70.0},"calculated_at":"2026-08-13T14:30:53.187578Z"},{"id":"3635c6f5-dab9-4196-8c31-190a6fe2628d","threat_type":"cve","title":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce","summary":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS.\n\nThis issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T15:19:39.213000Z","last_modified_at":"2026-08-13T15:31:50.082769Z","external_id":"CVE-2026-28154","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS.\n\nThis issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7.","affected_products":[],"references":["https://patchstack.com/database/wordpress/theme/manh/vulnerability/wordpress-m-anh-theme-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","https://patchstack.com/database/wordpress/theme/samex/vulnerability/wordpress-samex-clean-minimal-shop-woocommerce-wordpress-theme-theme-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-79"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.1,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T15:31:55.454352Z"},{"id":"11752e6b-5fde-4eec-bc7a-d569a9c3701a","threat_type":"cve","title":"Administrator SQL Injection in MailChimp For WooCommerce &lt; 6.2 versions.","summary":"Administrator SQL Injection in MailChimp For WooCommerce &lt; 6.2 versions.","severity":"high","cvss_score":7.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:12.880000Z","last_modified_at":"2026-08-13T14:30:50.152063Z","external_id":"CVE-2026-73346","description":"Administrator SQL Injection in MailChimp For WooCommerce &lt; 6.2 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/mailchimp-for-woocommerce/vulnerability/wordpress-mailchimp-for-woocommerce-plugin-6-2-sql-injection-vulnerability?_s_id=cve"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-89"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.6,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T14:30:52.534596Z"},{"id":"ef27082e-b002-41c6-879f-22a993022994","threat_type":"cve","title":"Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce &lt;= 2.10.0 versions.","summary":"Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce &lt;= 2.10.0 versions.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:10.647000Z","last_modified_at":"2026-08-13T14:30:49.554113Z","external_id":"CVE-2026-66697","description":"Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce &lt;= 2.10.0 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/colissimo-shipping-methods-for-woocommerce/vulnerability/wordpress-colissimo-officiel-methodes-de-livraison-pour-woocommerce-plugin-2-10-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-79"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.1,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T14:30:52.181902Z"},{"id":"31d471c4-2486-42f0-be83-1da9ea6a050f","threat_type":"cve","title":"Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce &lt;= 1.30.36 versions.","summary":"Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce &lt;= 1.30.36 versions.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:09.207000Z","last_modified_at":"2026-08-13T14:30:48.887868Z","external_id":"CVE-2026-66655","description":"Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce &lt;= 1.30.36 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/multiparcels-shipping-for-woocommerce/vulnerability/wordpress-multiparcels-shipping-for-woocommerce-plugin-1-30-36-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-79"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.1,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T14:30:53.272807Z"},{"id":"39d3a304-20a3-4761-ac75-1a5ca9f544e6","threat_type":"cve","title":"Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce &lt;= 3.0.0 versions.","summary":"Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce &lt;= 3.0.0 versions.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:08.237000Z","last_modified_at":"2026-08-13T14:30:48.419465Z","external_id":"CVE-2026-66468","description":"Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce &lt;= 3.0.0 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/local-delivery-drivers-for-woocommerce/vulnerability/wordpress-local-delivery-drivers-for-woocommerce-plugin-3-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-79"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.1,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T14:30:52.091907Z"},{"id":"dee6cd62-c2ea-45cb-a942-15dabf6af067","threat_type":"cve","title":"Unauthenticated SQL Injection in Active Products Tables for WooCommerce &lt;= 1.1.1 versions.","summary":"Unauthenticated SQL Injection in Active Products Tables for WooCommerce &lt;= 1.1.1 versions.","severity":"critical","cvss_score":9.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:05.380000Z","last_modified_at":"2026-08-13T14:30:47.110521Z","external_id":"CVE-2026-66436","description":"Unauthenticated SQL Injection in Active Products Tables for WooCommerce &lt;= 1.1.1 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/profit-products-tables-for-woocommerce/vulnerability/wordpress-active-products-tables-for-woocommerce-plugin-1-1-1-sql-injection-vulnerability?_s_id=cve"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-89"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":9.3,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T14:30:51.919203Z"},{"id":"4e27de62-89a1-440a-803d-c07ae1ec77a4","threat_type":"cve","title":"The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling t","summary":"The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders.\n\nExploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6's optional order confirmation page module to be enabled.","severity":"high","cvss_score":8.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T06:17:38.120000Z","last_modified_at":"2026-08-13T15:31:46.043597Z","external_id":"CVE-2026-18945","description":"The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders.\n\nExploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6's optional order confirmation page module to be enabled.","affected_products":[],"references":["https://wpscan.com/vulnerability/0d43b739-90de-4bae-90c1-3acaee8888e6/"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-639"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":8.2,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T15:31:56.740157Z"}],"top_7d":[{"id":"90ffed6b-6227-41af-8acf-6d35c46c9ea8","threat_type":"cve","title":"The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unaut","summary":"The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-06T22:16:45.717000Z","last_modified_at":"2026-08-07T14:58:34.424010Z","external_id":"CVE-2026-13399","description":"The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments","affected_products":[],"references":["https://wpscan.com/vulnerability/6ae19ba0-26ba-4ffa-94e3-3fe32cedcae1/"],"sources":["nvd"],"score":90.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":true,"matched":["paypal"],"points":25},"cwe_match":{"hit":true,"matched":["CWE-639"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.5,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":90,"final_score":90.0},"calculated_at":"2026-08-13T02:00:16.453810Z"},{"id":"7e5ceddc-35de-4cf1-b91f-0d0b670b8c7d","threat_type":"cve","title":"Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access t","summary":"Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.","severity":"critical","cvss_score":10.0,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd","kev","actively-exploited"],"published_at":"2026-08-10T18:18:53.300000Z","last_modified_at":"2026-08-13T13:22:30.617064Z","external_id":"CVE-2026-72898","description":"Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.","affected_products":["cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*","cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*"],"references":["https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json","https://www.cve.org/CVERecord?id=CVE-2026-72898","https://www.metabase.com/blog/security-update","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72898"],"sources":["nvd","cisa_kev"],"score":80.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-89"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":10.0,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":true,"points":25},"actively_exploited":{"hit":true,"points":15},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":true,"source_count":2,"points":5},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":80,"final_score":80.0},"calculated_at":"2026-08-13T13:24:21.044872Z"},{"id":"8926f54b-4152-4d98-8191-461477dcb84f","threat_type":"cve","title":"The ShopEngine Elementor WooCommerce Builder Addon  WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, a","summary":"The ShopEngine Elementor WooCommerce Builder Addon  WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T06:17:38.230000Z","last_modified_at":"2026-08-13T15:31:46.109948Z","external_id":"CVE-2026-19088","description":"The ShopEngine Elementor WooCommerce Builder Addon  WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.","affected_products":[],"references":["https://wpscan.com/vulnerability/f58066e9-8066-43bc-8778-7ded279e8ee2/"],"sources":["nvd"],"score":75.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":true,"matched":["checkout"],"points":25},"cwe_match":{"hit":true,"matched":["CWE-352"],"points":20},"cvss_threshold":{"hit":false,"threshold":7.0,"cvss_score":5.4,"points":0},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":75,"final_score":75.0},"calculated_at":"2026-08-13T15:31:55.358847Z"},{"id":"d534ae26-7afb-4ad4-83b7-98dc90f0ff4c","threat_type":"cve","title":"Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart &lt;","summary":"Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart &lt;= 2.1.1 versions.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:07.960000Z","last_modified_at":"2026-08-13T14:30:48.292176Z","external_id":"CVE-2026-66466","description":"Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart &lt;= 2.1.1 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/storegrowth-sales-booster/vulnerability/wordpress-storegrowth-smart-sales-booster-for-woocommerce-bogo-upsells-direct-checkout-quick-view-side-cart-plugin-2-1-1-broken-access-control-vulnerability?_s_id=cve"],"sources":["nvd"],"score":70.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":true,"matched":["checkout"],"points":25},"cwe_match":{"hit":false,"matched":[],"points":0},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.5,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":70,"final_score":70.0},"calculated_at":"2026-08-13T14:30:53.247409Z"},{"id":"acfc00f8-889e-4890-a046-754033e51762","threat_type":"cve","title":"Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) &lt;= 1.0.7 versions.","summary":"Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) &lt;= 1.0.7 versions.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:05.120000Z","last_modified_at":"2026-08-13T14:30:46.983031Z","external_id":"CVE-2026-66431","description":"Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) &lt;= 1.0.7 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/clink-gateway-for-woocommerce/vulnerability/wordpress-bitcoin-lightning-payment-gateway-for-woocommerce-via-clink-plugin-1-0-7-broken-access-control-vulnerability?_s_id=cve"],"sources":["nvd"],"score":70.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":true,"matched":["payment gateway"],"points":25},"cwe_match":{"hit":false,"matched":[],"points":0},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.5,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":70,"final_score":70.0},"calculated_at":"2026-08-13T14:30:53.187578Z"},{"id":"f901f484-87b0-467c-8a1c-877e20310d42","threat_type":"cve","title":"The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in \"Sel","summary":"The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in \"Select\" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfixed vector from CVE-2025-12115, whose 2.2.0 fix only addressed applying a custom price to products where Name Your Price is disabled and left the Select-mode allowlist unenforced through 2.2.4.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-06T22:16:49.120000Z","last_modified_at":"2026-08-07T15:59:39.891857Z","external_id":"CVE-2026-16620","description":"The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in \"Select\" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfixed vector from CVE-2025-12115, whose 2.2.0 fix only addressed applying a custom price to products where Name Your Price is disabled and left the Select-mode allowlist unenforced through 2.2.4.","affected_products":[],"references":["https://wpscan.com/vulnerability/71e6ccc0-5626-4cce-986e-5591f5df92bd/"],"sources":["nvd"],"score":70.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":true,"matched":["merchant"],"points":25},"cwe_match":{"hit":false,"matched":[],"points":0},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.5,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":70,"final_score":70.0},"calculated_at":"2026-08-13T02:00:51.830868Z"},{"id":"3699063e-9753-4ab2-9f13-e2ee76d66b05","threat_type":"cve","title":"The Payment Gateway for Redsys &amp; WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider noti","summary":"The Payment Gateway for Redsys &amp; WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-06T22:16:45.333000Z","last_modified_at":"2026-08-07T17:00:31.131525Z","external_id":"CVE-2026-12584","description":"The Payment Gateway for Redsys &amp; WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.","affected_products":[],"references":["https://wpscan.com/vulnerability/1ff08062-8f2c-4542-b795-fe82bfa6040c/"],"sources":["nvd"],"score":70.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":true,"matched":["payment gateway"],"points":25},"cwe_match":{"hit":false,"matched":[],"points":0},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.5,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":70,"final_score":70.0},"calculated_at":"2026-08-13T02:00:50.151305Z"},{"id":"3635c6f5-dab9-4196-8c31-190a6fe2628d","threat_type":"cve","title":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce","summary":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS.\n\nThis issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T15:19:39.213000Z","last_modified_at":"2026-08-13T15:31:50.082769Z","external_id":"CVE-2026-28154","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS.\n\nThis issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7.","affected_products":[],"references":["https://patchstack.com/database/wordpress/theme/manh/vulnerability/wordpress-m-anh-theme-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","https://patchstack.com/database/wordpress/theme/samex/vulnerability/wordpress-samex-clean-minimal-shop-woocommerce-wordpress-theme-theme-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-79"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.1,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T15:31:55.454352Z"},{"id":"11752e6b-5fde-4eec-bc7a-d569a9c3701a","threat_type":"cve","title":"Administrator SQL Injection in MailChimp For WooCommerce &lt; 6.2 versions.","summary":"Administrator SQL Injection in MailChimp For WooCommerce &lt; 6.2 versions.","severity":"high","cvss_score":7.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:12.880000Z","last_modified_at":"2026-08-13T14:30:50.152063Z","external_id":"CVE-2026-73346","description":"Administrator SQL Injection in MailChimp For WooCommerce &lt; 6.2 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/mailchimp-for-woocommerce/vulnerability/wordpress-mailchimp-for-woocommerce-plugin-6-2-sql-injection-vulnerability?_s_id=cve"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-89"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.6,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T14:30:52.534596Z"},{"id":"ef27082e-b002-41c6-879f-22a993022994","threat_type":"cve","title":"Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce &lt;= 2.10.0 versions.","summary":"Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce &lt;= 2.10.0 versions.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T14:17:10.647000Z","last_modified_at":"2026-08-13T14:30:49.554113Z","external_id":"CVE-2026-66697","description":"Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce &lt;= 2.10.0 versions.","affected_products":[],"references":["https://patchstack.com/database/wordpress/plugin/colissimo-shipping-methods-for-woocommerce/vulnerability/wordpress-colissimo-officiel-methodes-de-livraison-pour-woocommerce-plugin-2-10-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"sources":["nvd"],"score":65.0,"score_breakdown":{"technology_match":{"hit":true,"matched":["WooCommerce"],"points":30},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-79"],"points":20},"cvss_threshold":{"hit":true,"threshold":7.0,"cvss_score":7.1,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":65,"final_score":65.0},"calculated_at":"2026-08-13T14:30:52.181902Z"}],"stats":{"total_threats":103596,"critical_count":176,"high_count":24,"average_score":12.06,"sources_active":["cisa_kev","github_advisories","nvd"]}}