Vanquish develops a focused line of WordPress and WooCommerce plugins, including customer management, support ticketing, and file-upload utilities, that extend e-commerce and site administration functionality. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across its plugin portfolio through web-tier weakness classes including CSRF, path traversal, missing authorization, unrestricted file uploads, and cross-site scripting—patterns endemic to form-handling and file-processing plugins that execute in a shared WordPress environment. Defenders should treat updates to these plugins as a patching priority for any WordPress installation relying on them; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vanquish over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0399HIGH The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exp | Apr 15, 2024 | 8.1 | 34 | NO | YES |
CVE-2024-11150CRITICAL The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in | Nov 13, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-10627CRITICAL The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() functi | Nov 9, 2024 | 9.8 | 29 | NO | NO |
CVE-2021-24171CRITICAL The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file | Apr 5, 2021 | 9.8 | 29 | NO | NO |
CVE-2024-10820CRITICAL The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, | Nov 13, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-10625CRITICAL The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() funct | Nov 9, 2024 | 9.1 | 27 | NO | NO |
CVE-2025-69376HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue aff | Feb 20, 2026 | 8.6 | 26 | NO | NO |
CVE-2024-13343HIGH The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new_roles() function in all versio | Feb 1, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-69377HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue aff | Feb 20, 2026 | 7.7 | 24 | NO | NO |
CVE-2024-10626HIGH The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function | Nov 9, 2024 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vanquish.
Media articles that mention a CVE ID that affects a product developed by Vanquish — matched by CVE ID, not by vendor name.