Acowebs develops a focused line of WooCommerce plugins for e-commerce functionality such as product labeling, invoicing, and dynamic pricing, presenting a niche but interconnected attack surface within the WordPress ecosystem. The vendor's disclosures concentrate on input-handling and data-processing weaknesses, including SQL injection, cross-site scripting, deserialization flaws, and injection-class vulnerabilities that are characteristic of plugins operating at the application layer of a web framework. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acowebs over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47588CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynamic-pricing allows Code Injection | Nov 6, 2025 | 9.8 | 29 | NO | NO |
CVE-2024-1773HIGH The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 via deserialization of unt | Mar 7, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-30230HIGH Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/ | Mar 28, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-47544HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynamic-pr | May 7, 2025 | 7.2 | 20 | NO | NO |
CVE-2024-24886MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acowebs Product Labels For Woocommerce (Sale Badges) allows Stored XSS.This is | Feb 8, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-12109MEDIUM The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perfo | Mar 25, 2025 | 4.1 | 14 | NO | NO |
CVE-2024-10638MEDIUM The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perf | Mar 25, 2025 | 4.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acowebs.
Media articles that mention a CVE ID that affects a product developed by Acowebs — matched by CVE ID, not by vendor name.