CVE Tools

Woo

10 CVEs tracked since 2024. Since Jun 2024, none of them reached CISA KEV.

Woo CVEs per month

Jun 2024 to Jun 2024. Point at a month, or focus the strip and use the arrow keys.
Woo CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-06100

Products

The products that kept showing up in Woo's monthly top three, with their CVEs summed over those months.

  1. Woocommerce Warranty Requests31 month
  2. Woocommerce Product Vendors21 month
  3. Woocommerce Ship To Multiple Addresses21 month

Latest CVEs

The 14 most recently published vulnerabilities affecting Woo.

  1. CVE-2023-50850WordPress Woo Subscriptions plugin < 5.8.0 - Broken Access Control vulnerability4.3
  2. CVE-2017-20193Product Vendors <= 2.0.35 - Reflected Cross Site Scripting4.7
  3. CVE-2023-37872WordPress WooCommerce Ship to Multiple Addresses plugin <= 3.8.5 - Broken Access Control vulnerability6.5
  4. CVE-2023-36512WordPress AutomateWoo plugin <= 5.7.5 - Broken Access Control vulnerability6.5
  5. CVE-2023-37870WordPress WooCommerce Warranty Requests plugin <= 2.1.9 - Broken Access Control vulnerability8.1
  6. CVE-2023-51495WordPress WooCommerce Warranty Requests plugin <= 2.2.7 - Broken Access Control vulnerability6.5
  7. CVE-2023-51496WordPress WooCommerce Warranty Requests plugin <= 2.2.7 - Broken Access Control vulnerability5.3
  8. CVE-2023-51497WordPress WooCommerce Ship to Multiple Addresses plugin <= 3.8.9 - Broken Access Control vulnerability5.4
  9. CVE-2023-51498WordPress WooCommerce Canada Post Shipping plugin <= 2.8.3 - Broken Access Control vulnerability5.3
  10. CVE-2023-52186WordPress WooCommerce Product Vendors plugin <= 2.2.2 - Unauthenticated Broken Access Control vulnerability5.3
  11. CVE-2023-34003WordPress WooCommerce Box Office plugin <= 1.1.51 - Unauthenticated Save Ticket Barcode vulnerability6.5
  12. CVE-2023-51494WordPress WooCommerce Product Vendors plugin <= 2.2.1 - Broken Access Control vulnerability5.3
  13. CVE-2023-33331WordPress WooCommerce Product Vendors Plugin <= 2.1.76 is vulnerable to SQL Injection8.5
  14. CVE-2023-35879WordPress WooCommerce Product Vendors Plugin <= 2.1.78 is vulnerable to SQL Injection7.6

The record

Peak rank
#73 in Jun 2024
Busiest month shown
Jun 2024, 10 CVEs
Months with a KEV entry
0 since Jun 2024
Monthly snapshots
1 since 2024
Woo's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store