References https://www.cnvd.org.cn/flaw/show/CNVD-2026-16588 https://helpx.adobe.com/security/products/magento/apsb26-05.html https://nvd.nist.gov/vuln/detail/CVE-2025-54236 https://helpx.adobe.com/security/products/magento/apsb25-88.html https://cve.imfht.com/poc_detail/02344e573422ceafcc99cdee22db2336ad216272?lang=en https://www.cnvd.org.cn/flaw/show/CNVD-2021-102804 https://helpx.adobe.com/security/products/magento/apsb22-12.html https://nvd.nist.gov/vuln/detail/CVE-2022-24086 https://avd.aliyun.com/detail?id=AVD-2019-7928 https://zone.ci/aliyun/ali_nvd/86293.html
Related VulnerabilitiesPoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege EscalationPoCCVE-2026-71362: Adobe Commerce/Magento - Customer Session Identity SwitchPoCCVE-2026-27542: WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Unauthenticated Privilege EscalationPoCCVE-2026-3891: Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File UploadPoCCVE-2026-53787: Magento 2 Amasty Order Attributes < 4.0.0 - Unauthenticated Arbitrary File UploadWordPress TI WooCommerce Wishlist /wp-json/wc/v3/wishlist/get_products SQL 注入漏洞(CVE-2024-43917)PoCCVE-2025-13339: Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadPoCCVE-2025-13773: WordPress Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Remote Code ExecutionPoCCVE-2026-10580: Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account TakeoverPoCCVE-2026-49777: WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCEWordPress WooCommerce OrderConvo 插件 /wp-json/wooconvo/v1/download-file 文件读取漏洞(CVE-2025-10162)PoCCVE-2025-47577: TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File UploadPoCCVE-2025-10897: WooCommerce Designer Pro <= 1.9.28 - Arbitrary File Read