Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High1
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-08-15

CVE-2025-6025 - Order Tip For Woocommerce Plugin

The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all versions up to, and including, 1.5.4. This is due to lack of server-side validation on the `data-tip` attribute, which makes it possible for unauthenticated attackers to apply an excessive or even negative tip amount, resulting in unauthorized discount up to free orders depending on the value submitted.

PLUGIN Order Tip For Woocommerce

CVE-2025-6025

HIGH CVSS 7.5 2025-08-15
Threat Entry Updated 2024-11-21

CVE-2024-1119 - Order Tip For Woocommerce Plugin

The Order Tip for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_tips_to_csv() function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to export the plugin's order fees.

PLUGIN Order Tip For Woocommerce

CVE-2024-1119

MEDIUM CVSS 5.3 2024-03-20
Scroll to top