Hippoo Mobile App for WooCommerce <= 1.9.5 - Missing Authorization
medium
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.6
- Disclosed:
- Jun 8, 2026
CVE-2026-49065 on NVD →
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
critical
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both administrat...
- CVSS:
- 9.8
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.5
- Disclosed:
- Jun 5, 2026
CVE-2026-10580 on NVD →
Hippoo Mobile App for WooCommerce [hippoo] < 1.7.2
unknown
[en] The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, and including, 1.7.1. This is due to the REST API endpoint `/wp-json/hippoo/v1/wc/token/save_callback/{token_id}` being registered with `permission_callback => '...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Dec 12, 2025
CVE-2025-12655 on NVD →
Hippoo Mobile App for WooCommerce <= 1.7.1 - Missing Authorization to Unauthenticated Limited File Write
medium
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, and including, 1.7.1. This is due to the REST API endpoint `/wp-json/hippoo/v1/wc/token/save_callback/{token_id}` being registered with `permission_callback => '__ret...
- CVSS:
- 5.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Dec 11, 2025
CVE-2025-12655 on NVD →
Hippoo Mobile App for WooCommerce [hippoo] < 1.7.2
unknown
[en] The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive inform...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Dec 10, 2025
CVE-2025-13339 on NVD →
Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read
high
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information...
- CVSS:
- 7.5
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Dec 9, 2025
CVE-2025-13339 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database