Vulnerabilities
Summary — last 7 days
New vulnerabilities2,833▲ 192 vs. last week
Critical / high1,314▼ 122 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)250▲ 236 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.4) | 0.34% | — | Wpclever WPC Composite ProductsAI | 4/27/2024 | 6/17/2026 | The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wooco_components[0][name]' parameter in all versions up to, and including, 7.2.7 due to insufficient input sanitization and output escaping and missing authorization on the ajax_save_components… | |
| Modified | Medium (6.1) | 0.40% | — | Woocommerce Composite Products | 8/30/2023 | 6/17/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Composite Products plugin <= 8.7.5 versions. |