Oxygen MyData for WooCommerce
Oxygen MyData for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 9.1, and the most serious one scores 9.1 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Path Traversal, behind 1 of the records (100%).
The one issue recorded for Oxygen MyData for WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by LVT-tholv2k. Oxygen MyData for WooCommerce is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-32631Oxygen MyData for WooCommerce <= 1.0.64 - Unauthenticated Arbitrary File Deletion
Read the full analysisVulnerability Records

Oxygen MyData for WooCommerce
Author
oxygensuite
Automatically issue invoices & receipts from your eshop. Connecting the eshop (woocommerce) with your Oxygen ERP is now an extremely useful tool for your business. This interface permits the optimization of all operations and saves valuable time. Oxygen offers a complete solution with the Oxygen WooCommerce plugin, which allows eshops to be connected with Oxygen Pelatologio ERP using an API Key. With the woocommerce plugin from Oxygen you can: -Transfer orders from eshop to ERP -Automatically create customer contacts from eshop to Oxygen -Automatically issue of receipts and invoices in Oxygen without additional ECR (using the myData provider) -View and automatically send PDF documents to customers -Manage order status -NEW:Set document payment status (e.g. “Paid”) based on WooCommerce payment method -NEW:Issue intra-community invoices (EU customers) -NEW:Select to issue only retail receipts (not invoices) -NEW: Ability to select Oxygen Checkout for card/iris billing -NEW: IRIS payments via Oxygen Payments with automatic ERP sync -NEW: Automatic receipts and invoices upload to Skroutz for marketplace orders (skroutz integration is required) An account with https://www.pelatologio.gr/ is required. An update to the latest version is required to maintain Oxygen Payments functionality (due to IRIS update). Notes Ensure WooCommerce is active before using this plugin. You must have an account in pelatologio app If ui (css/js) is not working as expected, please delete cache files and try again
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C