Add Customer for WooCommerce

Add Customer for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Add Customer for WooCommerce has a vendor fix available, so running the current release closes it.

All of these findings were reported by Dhabaleshwar Das. Add Customer for WooCommerce is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Add Customer for WooCommerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2024-24841

Add Customer for WooCommerce <= 1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Add Customer for WooCommerce banner
Latestv1.9.6

Add Customer for WooCommerce

dansart

Author

dansart

5.0(12)
100/100
Last Updated
2026-09-07 (6d ago)
Active Installs
1,000+
Downloads
28,652
Requires WP
5.4.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2020-12-01 (6y ago)

This plugin is designed to simplify the process of creating new users/customers. It’s particularly useful if you receive client orders via phone or email and want to integrate these orders into WooCommerce for stock and order management. The plugin adds a checkbox at the end of the billing address form. When this box is checked, it creates a new user with the role “customer.” If an email is not provided, the plugin generates a unique one using your site’s domain as the email domain and the customer’s name as the local part (e.g., firstname.lastname@your-site.com). You have the option to customize this auto-generated email format. Try it out for free with TasteWP: https://tastewp.com/new?pre-installed-plugin-slug=woocommerce%2Cadd-customer-for-woocommerce By default, the newly created user does not receive any emails during account creation, though they will probably on order updates. In the settings menu, there are options to: – Check the box by default – Send login credentials to the new customer There are also additional options: – Update new customer information by default – Link customer orders – Define the user role individually – Set the user role for new customers – Customize the auto-generated email format – Edit the email subject for accounts created – Change the sender’s email address Settings Menu: WooCommerce -> Add customer settings Required Plugins: WooCommerce 4.7.0 or higher Required PHP extension: Intl If you like the plugin, please leave some stars or buy me a coffee. Thank you!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C