VYPR

empik-for-woocommerce

by WordPress

CVEs (2)

  • CVE-2025-32568CriApr 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object Injection.This issue affects EmpikPlace for Woocommerce: from n/a through <= 1.4.3.

  • CVE-2026-9766MedSep 19, 2026
    risk 0.28cvss 4.3epss 0.00

    The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…