Woocommerce
44 CVEs tracked since 2023. Since May 2023, none of them reached CISA KEV.
Woocommerce CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-05 | 4 | 0 |
| 2023-06 | 7 | 0 |
| 2023-07 | 6 | 0 |
| 2023-08 | 8 | 0 |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | 12 | 0 |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | 7 | 0 |
Products
The products that kept showing up in Woocommerce's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Woocommerce.
- CVE-2025-14073WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information Disclosure5.3
- CVE-2022-50972WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php9.8
- CVE-2026-2381WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter6.5
- CVE-2026-9284WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure8.2
- CVE-2026-1710WooPayments <= 10.5.1 - Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajax6.5
- CVE-2025-13457WooCommerce Square <= 5.1.1 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in get_token_by_id7.5
- CVE-2025-5062WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting6.1
- CVE-2024-10486Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File5.3
- CVE-2020-36841WooCommerce Smart Coupons <= 4.6.0 - Unauthenticated Coupon Creation5.3
- CVE-2017-20193Product Vendors <= 2.0.35 - Reflected Cross Site Scripting4.7
- CVE-2024-9944WooCommerce <= 9.0.2 - Unauthenticated HTML Injection5.3
- CVE-2023-35049WordPress WooCommerce Stripe Payment Gateway plugin <= 7.4.0 - Unauthenticated Broken Access Control vulnerability7.5
- CVE-2023-51495WordPress WooCommerce Warranty Requests plugin <= 2.2.7 - Broken Access Control vulnerability6.5
- CVE-2023-51496WordPress WooCommerce Warranty Requests plugin <= 2.2.7 - Broken Access Control vulnerability5.3
- CVE-2023-51497WordPress WooCommerce Ship to Multiple Addresses plugin <= 3.8.9 - Broken Access Control vulnerability5.4
The record
- Peak rank
- #64 in Dec 2023
- Busiest month shown
- Dec 2023, 12 CVEs
- Months with a KEV entry
- 0 since May 2023
- Monthly snapshots
- 6 since 2023