VYPR

Woocommerce Square

by WordPress

Source repositories

CVEs (2)

  • CVE-2023-35876HigDec 20, 2023
    risk 0.53cvss 8.1epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.

  • CVE-2025-13457HigJan 10, 2026
    risk 0.42cvss 7.5epss 0.00

    The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to…