Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tychesoftwares

First CVE: May 16, 2023Active for: 3 yearsTotal CVEs: 46
36.4
VTI Score
Medium

Tychesoftwares develops a focused set of WordPress and WooCommerce plugins that extend e-commerce functionality and order management for online merchants, positioning them within widely used WordPress plugin ecosystems where vulnerabilities can reach a broad deployment base. Vulnerabilities affecting the vendor skew toward serious outcomes, reaching critical severity, and frequently acquire public exploit code, reflecting the accessibility and web-facing nature of WordPress plugins. The exposure recurs across products such as Arconix Shortcodes, Abandoned Cart Lite for WooCommerce, and Order Delivery Date plugins through a consistent pattern of input-validation and authorization weaknesses—cross-site scripting, cross-site request forgery, missing authorization, and authentication bypass—that are endemic to web application plugins handling user input and administrative functions. Defenders should treat these plugins as regular patching targets and monitor for exploitation of authorization gaps in cart and order-management features; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tychesoftwares over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2023
3 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2986CRITICAL
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption
Jun 8, 20239.866NOYES
CVE-2025-13773CRITICAL
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Deli
Dec 24, 20259.847NOYES
CVE-2025-2907CRITICAL
The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update o
Apr 26, 20259.839NOYES
CVE-2026-56060HIGH
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
Jun 26, 20267.530NONO
CVE-2026-42386CRITICAL
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
Jun 15, 20269.330NONO
CVE-2024-13359CRITICAL
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_or
Mar 8, 20259.830NONO
CVE-2019-25152MEDIUM
The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versio
Jun 22, 20236.129NOYES
CVE-2023-41858HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions.
Oct 10, 20238.826NONO
CVE-2022-45367HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Custom Order Numbers for WooCommerce plugin <= 1.4.0 versions.
May 25, 20238.826NONO
CVE-2026-25317HIGH
Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Cont
Mar 25, 20267.525NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
67%
22%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network46 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low45 (97.8%)
High1 (2.2%)
Unknown0 (0.0%)
User Interaction
None20 (43.5%)
Unknown0 (0.0%)
Required26 (56.5%)
Privileges Required
Low13 (28.3%)
High2 (4.3%)
None31 (67.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
8.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tychesoftwares.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tychesoftwares — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tychesoftwares's Products

View all 3 CNAs →

Top CWEs