Product Notices for WooCommerce

Tried inquiring about an older (from February 2025) CVE related to this plugin in the WordPress forum. A moderator silently deleted the post. You can read the details of that here. I then reached out to the plugin author via an email address I found for him. No reply. I decided to turn to AI for help.

ChatGPT was asked to examine the plugin file, and determined the following: The uploaded Product Notices for WooCommerce 1.3.4 is vulnerable to CVE-2025-31807. NVD now identifies versions through 1.3.4 as affected, while Patchstack still lists no official patch and a CVSS score of 4.3. Patchstack records the report date as February 28, 2025.

I asked ChatGPT for recommendations. The quite detailed response can be read here. That post includes a link where can download a patched and upgraded version of the plugin, if you want it.

Scroll to Top