Shipping with Venipak for WooCommerce
Shipping with Venipak for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Shipping with Venipak for WooCommerce has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Shipping with Venipak for WooCommerce is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-24553Shipping with Venipak for WooCommerce <= 1.22.4 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Shipping with Venipak for WooCommerce
Author
Akadrama
woocommerceDelivery to customer address. Delivery to Venipak pickup points and lockers. A pickup map is displayed during checkout for user convenience. Cash on delivery (COD) service for collection of money by cash or card. To use this extension, you must have an active contract with Venipak. https://www.venipak.com/ Additionally, you must have user credentials for the Venipak API. Please contact Venipak sales. https://www.venipak.com/ Support email: hello@akadrama.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C