← WordPress Vulnerabilities
WordPress security by component

Hippoo Mobile App for WooCommerce

Hippoo Mobile App for WooCommerce is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: hippoo

CVE-2026-49065: Hippoo Mobile App for WooCommerce: A security weakness

Hippoo Mobile App for WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.9.5.

PublishedJun 15, 2026
Known safe version1.9.6
Safe version
Jun 15, 2026 CVE-2026-49065
Hippoo Mobile App for WooCommerce: A security weakness
Hippoo Mobile App for WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.9.5.
1.9.6
CVE8.2
NVDPending
Jun 11, 2026 CVE-2026-49060
Hippoo Mobile App for WooCommerce: Privilege escalation or authentication bypass
Hippoo Mobile App for WooCommerce is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 1.9.4.
1.9.5
CVE9.8
NVDPending
Jun 05, 2026 CVE-2026-10580
Hippoo Mobile App for WooCommerce: Privilege escalation or authentication bypass
Hippoo Mobile App for WooCommerce is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 1.9.4.
> 1.9.4
CVE9.8
NVDPending
Dec 12, 2025 CVE-2025-12655
Hippoo Mobile App for WooCommerce: A security weakness
Hippoo Mobile App for WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending