Skip to content
jproxx
← Back to the blog

Posts on the topic: WooCommerce

Security

Security Bulletin — July 24, 2026: Unpaid Orders Marked "Paid" — Payment Manipulation in the Stripe Plugin for WooCommerce, plus Privilege Escalation in EventON and Data Loss in Easy Appointments (CVE-2026-12654, CVE-2026-10033 & CVE-2026-8789)

Three WordPress flaws published on July 24, 2026: an unauthenticated order-status manipulation in the Stripe payment plugin for WooCommerce (payment fraud), an unauthenticated privilege escalation in EventON Action User, and a high-rated data-deletion flaw in Easy Appointments.

Read more →
Security

Security Bulletin — July 23, 2026: Two Login-Free Flaws in Shop and Form Plugins — SQL Injection in Lumise Product Designer (WooCommerce) and Stored XSS in FormCraft (CVE-2026-9713 & CVE-2026-7232)

Two WordPress flaws published on July 23, 2026, both exploitable without a login: unauthenticated SQL injection in Lumise Product Designer for WooCommerce and unauthenticated stored XSS in FormCraft. Plus a note on the still actively exploited core flaw of the wp2shell chain.

Read more →
Security

Security Bulletin — July 20, 2026: Three Unauthenticated WordPress Plugin Flaws — SQL Injection, Path Traversal, and Stored XSS (CVE-2026-11349, CVE-2026-12898 & CVE-2026-10081)

Three WordPress plugin vulnerabilities from July 20, 2026, all exploitable without login: SQL injection in Modern Events Calendar, path traversal in All-in-One WP Migration, and stored XSS in Unlimited Elements.

Read more →
Security

Security Bulletin — July 17, 2026: Two Critical Unauthenticated Takeover Flaws in Bricksforge and AI Copilot — Plus Privilege Escalation and Shop Payment Fraud

Unauthenticated admin takeover in Bricksforge (CVSS 9.8) and in the AI Copilot plugin (CVSS 9.8), privilege escalation in User Registration & Membership, and a forged payment callback in the PhonePe gateway.

Read more →