plugin

Hippoo Vulnerabilities

6 known security issues reported for the Hippoo WordPress plugin. Most recent disclosed Jun 8, 2026.

1 critical 1 high 2 medium

Running Hippoo on your site? Check whether your installed version is affected.

Scan your site free

Hippoo Mobile App for WooCommerce <= 1.9.5 - Missing Authorization

medium

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.9.5
Fixed in:
1.9.6
Disclosed:
Jun 8, 2026

CVE-2026-49065 on NVD →

Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API

critical

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both administrat...

CVSS:
9.8
Affected:
up to 1.9.4
Fixed in:
1.9.5
Disclosed:
Jun 5, 2026

CVE-2026-10580 on NVD →

Hippoo Mobile App for WooCommerce [hippoo] < 1.7.2

unknown

[en] The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, and including, 1.7.1. This is due to the REST API endpoint `/wp-json/hippoo/v1/wc/token/save_callback/{token_id}` being registered with `permission_callback => '...

Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
Dec 12, 2025

CVE-2025-12655 on NVD →

Hippoo Mobile App for WooCommerce <= 1.7.1 - Missing Authorization to Unauthenticated Limited File Write

medium

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, and including, 1.7.1. This is due to the REST API endpoint `/wp-json/hippoo/v1/wc/token/save_callback/{token_id}` being registered with `permission_callback => '__ret...

CVSS:
5.3
Affected:
up to 1.7.1
Fixed in:
1.7.2
Disclosed:
Dec 11, 2025

CVE-2025-12655 on NVD →

Hippoo Mobile App for WooCommerce [hippoo] < 1.7.2

unknown

[en] The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive inform...

Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
Dec 10, 2025

CVE-2025-13339 on NVD →

Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read

high

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information...

CVSS:
7.5
Affected:
up to 1.7.1
Fixed in:
1.7.2
Disclosed:
Dec 9, 2025

CVE-2025-13339 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database