{"schema_version":1,"title":"BeRocket vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in BeRocket: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-15648, was published on 24 July 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/berocket","json_url":"https://junglewise.ai/threats/vendors/berocket.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/berocket","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":8,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":8},"latest":[{"cve":"CVE-2026-15648","cvss":6.4,"slug":"cve-2026-15648-berocket-brands-for-woocommerce-stored-xss-in-width-shortcode","title":"BeRocket Brands for WooCommerce Stored XSS in width shortcode attribute","severity":"medium","exploited":false,"published_at":"2026-07-24T08:16:26.16+00:00","url":"https://junglewise.ai/threats/cve-2026-15648-berocket-brands-for-woocommerce-stored-xss-in-width-shortcode"},{"cve":"CVE-2026-15794","cvss":6.4,"slug":"cve-2026-15794-berocket-grid-list-view-for-woocommerce-stored-xss-in-shortcode","title":"BeRocket Grid/List View for WooCommerce Stored XSS in Shortcode","severity":"medium","exploited":false,"published_at":"2026-07-23T10:16:51.333+00:00","url":"https://junglewise.ai/threats/cve-2026-15794-berocket-grid-list-view-for-woocommerce-stored-xss-in-shortcode"},{"cve":"CVE-2026-15647","cvss":4.4,"slug":"cve-2026-15647-berocket-brands-for-woocommerce-stored-xss-in-br-brand-tooltip","title":"BeRocket Brands for WooCommerce Stored XSS in br_brand_tooltip","severity":"medium","exploited":false,"published_at":"2026-07-23T10:16:50.943+00:00","url":"https://junglewise.ai/threats/cve-2026-15647-berocket-brands-for-woocommerce-stored-xss-in-br-brand-tooltip"},{"cve":"CVE-2026-15646","cvss":6.4,"slug":"cve-2026-15646-berocket-brands-for-woocommerce-stored-xss-in-style-shortcode","title":"BeRocket Brands for WooCommerce Stored XSS in style shortcode attribute","severity":"medium","exploited":false,"published_at":"2026-07-23T10:16:50.817+00:00","url":"https://junglewise.ai/threats/cve-2026-15646-berocket-brands-for-woocommerce-stored-xss-in-style-shortcode"},{"cve":"CVE-2026-57758","cvss":7.1,"slug":"cve-2026-57758-berocket-permalink-manager-for-woocommerce-csrf-to-stored-xss","title":"BeRocket Permalink Manager for WooCommerce CSRF to Stored XSS","severity":"high","exploited":false,"published_at":"2026-07-02T12:17:41.81+00:00","url":"https://junglewise.ai/threats/cve-2026-57758-berocket-permalink-manager-for-woocommerce-csrf-to-stored-xss"},{"cve":"CVE-2026-39437","cvss":7.1,"slug":"cve-2026-39437-woocommerce-min-max-step-quantity-limits-manager-unauthenticated","title":"WooCommerce Min Max Step Quantity Limits Manager unauthenticated XSS","severity":"high","exploited":false,"published_at":"2026-06-16T10:16:26.97+00:00","url":"https://junglewise.ai/threats/cve-2026-39437-woocommerce-min-max-step-quantity-limits-manager-unauthenticated"},{"cve":"CVE-2022-45813","cvss":5.4,"slug":"cve-2022-45813-berocket-advanced-ajax-product-filters-missing-authorization","title":"BeRocket Advanced AJAX Product Filters missing authorization","severity":"medium","exploited":false,"published_at":"2026-06-11T12:16:28.563+00:00","url":"https://junglewise.ai/threats/cve-2022-45813-berocket-advanced-ajax-product-filters-missing-authorization"},{"cve":"CVE-2025-11993","cvss":8.8,"slug":"cve-2025-11993-woocommerce-infinite-scroll-and-ajax-pagination-php-object","title":"WooCommerce Infinite Scroll and Ajax Pagination PHP Object Injection","severity":"high","exploited":false,"published_at":"2026-05-29T07:16:13.73+00:00","url":"https://junglewise.ai/threats/cve-2025-11993-woocommerce-infinite-scroll-and-ajax-pagination-php-object"}],"vendor":{"hub":true,"name":"BeRocket","slug":"berocket","homepage":"https://berocket.com/","description":"A developer of WordPress plugins focused on e-commerce functionality.","url":"https://junglewise.ai/threats/vendors/berocket"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-11993","cvss":8.8,"slug":"cve-2025-11993-woocommerce-infinite-scroll-and-ajax-pagination-php-object","title":"WooCommerce Infinite Scroll and Ajax Pagination PHP Object Injection","severity":"high","exploited":false,"published_at":"2026-05-29T07:16:13.73+00:00","url":"https://junglewise.ai/threats/cve-2025-11993-woocommerce-infinite-scroll-and-ajax-pagination-php-object"},{"cve":"CVE-2026-57758","cvss":7.1,"slug":"cve-2026-57758-berocket-permalink-manager-for-woocommerce-csrf-to-stored-xss","title":"BeRocket Permalink Manager for WooCommerce CSRF to Stored XSS","severity":"high","exploited":false,"published_at":"2026-07-02T12:17:41.81+00:00","url":"https://junglewise.ai/threats/cve-2026-57758-berocket-permalink-manager-for-woocommerce-csrf-to-stored-xss"},{"cve":"CVE-2026-39437","cvss":7.1,"slug":"cve-2026-39437-woocommerce-min-max-step-quantity-limits-manager-unauthenticated","title":"WooCommerce Min Max Step Quantity Limits Manager unauthenticated XSS","severity":"high","exploited":false,"published_at":"2026-06-16T10:16:26.97+00:00","url":"https://junglewise.ai/threats/cve-2026-39437-woocommerce-min-max-step-quantity-limits-manager-unauthenticated"},{"cve":"CVE-2026-15648","cvss":6.4,"slug":"cve-2026-15648-berocket-brands-for-woocommerce-stored-xss-in-width-shortcode","title":"BeRocket Brands for WooCommerce Stored XSS in width shortcode attribute","severity":"medium","exploited":false,"published_at":"2026-07-24T08:16:26.16+00:00","url":"https://junglewise.ai/threats/cve-2026-15648-berocket-brands-for-woocommerce-stored-xss-in-width-shortcode"},{"cve":"CVE-2026-15794","cvss":6.4,"slug":"cve-2026-15794-berocket-grid-list-view-for-woocommerce-stored-xss-in-shortcode","title":"BeRocket Grid/List View for WooCommerce Stored XSS in Shortcode","severity":"medium","exploited":false,"published_at":"2026-07-23T10:16:51.333+00:00","url":"https://junglewise.ai/threats/cve-2026-15794-berocket-grid-list-view-for-woocommerce-stored-xss-in-shortcode"},{"cve":"CVE-2026-15646","cvss":6.4,"slug":"cve-2026-15646-berocket-brands-for-woocommerce-stored-xss-in-style-shortcode","title":"BeRocket Brands for WooCommerce Stored XSS in style shortcode attribute","severity":"medium","exploited":false,"published_at":"2026-07-23T10:16:50.817+00:00","url":"https://junglewise.ai/threats/cve-2026-15646-berocket-brands-for-woocommerce-stored-xss-in-style-shortcode"},{"cve":"CVE-2022-45813","cvss":5.4,"slug":"cve-2022-45813-berocket-advanced-ajax-product-filters-missing-authorization","title":"BeRocket Advanced AJAX Product Filters missing authorization","severity":"medium","exploited":false,"published_at":"2026-06-11T12:16:28.563+00:00","url":"https://junglewise.ai/threats/cve-2022-45813-berocket-advanced-ajax-product-filters-missing-authorization"},{"cve":"CVE-2026-15647","cvss":4.4,"slug":"cve-2026-15647-berocket-brands-for-woocommerce-stored-xss-in-br-brand-tooltip","title":"BeRocket Brands for WooCommerce Stored XSS in br_brand_tooltip","severity":"medium","exploited":false,"published_at":"2026-07-23T10:16:50.943+00:00","url":"https://junglewise.ai/threats/cve-2026-15647-berocket-brands-for-woocommerce-stored-xss-in-br-brand-tooltip"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"BeRocket Brands-For-Woocommerce","slug":"brands-for-woocommerce","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/brands-for-woocommerce"}]}