Tychesoftwares develops a focused set of WordPress and WooCommerce plugins that extend e-commerce functionality and order management for online merchants, positioning them within widely used WordPress plugin ecosystems where vulnerabilities can reach a broad deployment base. Vulnerabilities affecting the vendor skew toward serious outcomes, reaching critical severity, and frequently acquire public exploit code, reflecting the accessibility and web-facing nature of WordPress plugins. The exposure recurs across products such as Arconix Shortcodes, Abandoned Cart Lite for WooCommerce, and Order Delivery Date plugins through a consistent pattern of input-validation and authorization weaknesses—cross-site scripting, cross-site request forgery, missing authorization, and authentication bypass—that are endemic to web application plugins handling user input and administrative functions. Defenders should treat these plugins as regular patching targets and monitor for exploitation of authorization gaps in cart and order-management features; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tychesoftwares over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2986CRITICAL The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption | Jun 8, 2023 | 9.8 | 66 | NO | YES |
CVE-2025-13773CRITICAL The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Deli | Dec 24, 2025 | 9.8 | 47 | NO | YES |
CVE-2025-2907CRITICAL The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update o | Apr 26, 2025 | 9.8 | 39 | NO | YES |
CVE-2026-56060HIGH Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions. | Jun 26, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-42386CRITICAL Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. | Jun 15, 2026 | 9.3 | 30 | NO | NO |
CVE-2024-13359CRITICAL The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_or | Mar 8, 2025 | 9.8 | 30 | NO | NO |
CVE-2019-25152MEDIUM The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versio | Jun 22, 2023 | 6.1 | 29 | NO | YES |
CVE-2023-41858HIGH Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions. | Oct 10, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-45367HIGH Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Custom Order Numbers for WooCommerce plugin <= 1.4.0 versions. | May 25, 2023 | 8.8 | 26 | NO | NO |
CVE-2026-25317HIGH Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Cont | Mar 25, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tychesoftwares.
Media articles that mention a CVE ID that affects a product developed by Tychesoftwares — matched by CVE ID, not by vendor name.