Browse all 4 CVE security advisories affecting Moreconvert Team. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Moreconvert Team develops marketing automation and conversion optimization software, primarily serving e-commerce businesses. Their products have historically been vulnerable to cross-site scripting (XSS) and remote code execution (RCE) flaws, often stemming from insufficient input validation and insecure deserialization. The team has addressed multiple privilege escalation vulnerabilities in their platform, allowing unauthorized access to administrative functions. While no major public security incidents have been documented, their four CVE records indicate a pattern of security weaknesses in web application components, particularly in user interaction points and API endpoints. Their security posture appears reactive rather than preventive, with vulnerabilities typically disclosed after independent researchers identify them.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-47487 | WordPress MC Woocommerce Wishlist plugin <= 1.9.1 - Cross Site Scripting (XSS) Vulnerability — MC Woocommerce WishlistCWE-79 | 7.1 | High | 2025-06-09 |
| CVE-2025-30879 | WordPress MC Woocommerce Wishlist plugin <= 1.8.9 - SQL Injection vulnerability — MC Woocommerce WishlistCWE-89 | 7.6 | High | 2025-03-27 |
| CVE-2024-34819 | WordPress MC Woocommerce Wishlist plugin <= 1.7.2 - Broken Access Control vulnerability — MC Woocommerce WishlistCWE-862 | 5.3 | Medium | 2024-06-11 |
| CVE-2024-34813 | WordPress WooCommerce Wishlist plugin <= 1.7.8 - Broken Access Control vulnerability — MC Woocommerce WishlistCWE-862 | 5.3 | Medium | 2024-06-11 |
This page lists every published CVE security advisory associated with Moreconvert Team. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.