VYPR

Order Listener for WooCommerce

by WordPress

CVEs (2)

  • CVE-2022-0948CriMay 9, 2022
    risk 0.64cvss 9.8epss 0.10

    The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

  • CVE-2025-68018CriJan 22, 2026
    risk 0.61cvss 9.4epss 0.00

    Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Listener for WooCommerce: from n/a through <= 3.6.1.