VYPR

Order Tip Woo

by WordPress

CVEs (2)

  • CVE-2025-6025HigAug 15, 2025
    risk 0.49cvss 7.5epss 0.00

    The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all versions up to, and including, 1.5.4. This is due to lack of server-side validation on the `data-tip` attribute, which makes it possible for unauthenticated…

  • CVE-2024-1119MedMar 20, 2024
    risk 0.34cvss 5.3epss 0.01

    The Order Tip for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_tips_to_csv() function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to export the…