Thisfunctional develops e-commerce extensions for WordPress, specifically the CTT Expresso Para WooCommerce plugin, which integrates payment and order-management functionality into online storefronts. Its observed vulnerability pattern centers on web-application input-handling and information-disclosure issues, including cross-site scripting, exposure of sensitive data, and improper logging practices that are characteristic of plugins bridging third-party payment systems with web platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thisfunctional over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6687HIGH The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via the /wp-content/uploads/cepw d | Aug 1, 2024 | 7.5 | 22 | NO | NO |
CVE-2022-47589MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <= 3.2.11 versions. | Mar 23, 2023 | 4.8 | 18 | NO | NO |
CVE-2024-6478MEDIUM The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform | May 15, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thisfunctional.
Media articles that mention a CVE ID that affects a product developed by Thisfunctional — matched by CVE ID, not by vendor name.