The WordPress Welcart e-Commerce plugin (20,000+ active installations) fixed multiple information disclosure vulnerabilities affecting version 2.2.7 and below.
The WordPress Advanced Shipment Tracking for WooCommerce (50,000+ active installations) fixed a critical vulnerability affection version 184.108.40.206 and below.
The WordPress Frontend File Manager plugin (2,000+ active installations) fixed multiple critical vulnerabilities affecting version 18.2 and below that could lead to content injection, privilege escalation, stored XSS, arbitrary file upload among several other issues.
Multiple WordPress plugins were found to be vulnerable to cross-site request forgery (CSRF) attacks.
The WordPress PWA for WP and AMP plugin (20,000+ active installations) fixed a critical broken access control vulnerability affecting version 1.7.32 and below that could lead to arbitrary file upload and remote code execution.