CVE Tools

Woocommerce

44 CVEs tracked since 2023. Since May 2023, none of them reached CISA KEV.

Woocommerce CVEs per month

May 2023 to Jun 2024. Point at a month, or focus the strip and use the arrow keys.
Woocommerce CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0540
2023-0670
2023-0760
2023-0880
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12120
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-0670

Products

The products that kept showing up in Woocommerce's monthly top three, with their CVEs summed over those months.

  1. Automatewoo52 months
  2. Woocommerce Pre-orders42 months
  3. Returns and Warranty Requests32 months
  4. Woocommerce Bookings21 month
  5. Woocommerce Follow-up Emails (Automatewoo)21 month
  6. Box Office11 month
  7. Brands11 month
  8. Bulk Stock Management11 month
  9. Gocardless11 month
  10. Paypal Payments11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Woocommerce.

  1. CVE-2025-14073WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information Disclosure5.3
  2. CVE-2022-50972WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php9.8
  3. CVE-2026-2381WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter6.5
  4. CVE-2026-9284WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure8.2
  5. CVE-2026-1710WooPayments <= 10.5.1 - Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajax6.5
  6. CVE-2025-13457WooCommerce Square <= 5.1.1 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in get_token_by_id7.5
  7. CVE-2025-5062WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting6.1
  8. CVE-2024-10486Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File5.3
  9. CVE-2020-36841WooCommerce Smart Coupons <= 4.6.0 - Unauthenticated Coupon Creation5.3
  10. CVE-2017-20193Product Vendors <= 2.0.35 - Reflected Cross Site Scripting4.7
  11. CVE-2024-9944WooCommerce <= 9.0.2 - Unauthenticated HTML Injection5.3
  12. CVE-2023-35049WordPress WooCommerce Stripe Payment Gateway plugin <= 7.4.0 - Unauthenticated Broken Access Control vulnerability7.5
  13. CVE-2023-51495WordPress WooCommerce Warranty Requests plugin <= 2.2.7 - Broken Access Control vulnerability6.5
  14. CVE-2023-51496WordPress WooCommerce Warranty Requests plugin <= 2.2.7 - Broken Access Control vulnerability5.3
  15. CVE-2023-51497WordPress WooCommerce Ship to Multiple Addresses plugin <= 3.8.9 - Broken Access Control vulnerability5.4

The record

Peak rank
#64 in Dec 2023
Busiest month shown
Dec 2023, 12 CVEs
Months with a KEV entry
0 since May 2023
Monthly snapshots
6 since 2023
Woocommerce's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store