Zorem's vulnerability footprint centers on a narrow line of e-commerce plugins for WooCommerce—including advanced local pickup, shipment tracking, and sales reporting tools—that extend checkout and order-management functionality for online retailers. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity, and recur through access-control and injection weaknesses including missing authorization checks, cross-site request forgery flaws, and SQL injection that are characteristic of web-facing administrative interfaces. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zorem over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41635HIGH Cross-Site Request Forgery (CSRF) vulnerability in Zorem Advanced Shipment Tracking for WooCommerce plugin <= 3.5.2 versions. | May 25, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-31283CRITICAL Missing Authorization vulnerability in zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.2. | Jun 9, 2024 | 9.8 | 24 | NO | NO |
CVE-2023-2841HIGH The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insuffi | Nov 22, 2023 | 7.2 | 21 | NO | NO |
CVE-2021-4347MEDIUM The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary optio | Jun 7, 2023 | 6.5 | 19 | NO | NO |
CVE-2022-38141MEDIUM Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8. | Jan 17, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-32814MEDIUM Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.1. | Jun 9, 2024 | 5.3 | 17 | NO | NO |
CVE-2022-40702MEDIUM Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.5.2. | Jan 17, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zorem.
Media articles that mention a CVE ID that affects a product developed by Zorem — matched by CVE ID, not by vendor name.