Pochipp
Pochipp has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 2 of the records (100%).
Every one of the 2 issues recorded for Pochipp has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Pochipp is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-66129Pochipp <= 1.18.0 - Missing Authorization
Read the full analysisVulnerability Records

Pochipp
Author
wppochipp
Amazonや楽天市場から商品を検索してアフィリエイトリンクを管理できるプラグインです。 詳しくは以下のページをご覧ください。 https://pochipp.com/Amazonや楽天市場から商品を検索してアフィリエイトリンクを管理できるプラグインです。 詳しくは以下のページをご覧ください。 https://pochipp.com/ 3RD PARTY RESOURCES Amazon PA-API WebSite: https://affiliate.amazon.co.jp/assoc_credentials/home Terms: https://affiliate.amazon.co.jp/help/operating/paapilicenseagreement Amazon Creaters API WebSite: https://affiliate.amazon.co.jp/help/operating/paapilicenseagreement Terms: https://affiliate.amazon.co.jp/help/operating/paapilicenseagreement Rakuten API WebSite: https://webservice.rakuten.co.jp/ Terms: https://webservice.rakuten.co.jp/guide/rule Yahoo 商品API WebSite: https://developer.yahoo.co.jp/webapi/shopping/item/ Terms: https://about.yahoo.co.jp/common/terms/index.html もしもアフィリエイト WebSite: https://af.moshimo.com/ Terms: https://af.moshimo.com/af/www/terms/shop
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C