Plugin BlueX for WooCommerce

Plugin BlueX for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Plugin BlueX for WooCommerce has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by NumeX. Plugin BlueX for WooCommerce is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Plugin BlueX for WooCommerce vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2025-68022

Plugin BlueX for WooCommerce <= 3.1.4 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv3.3.1

Plugin BlueX for WooCommerce

soporteblue

Author

soporteblue

1.7(3)
34/100
Last Updated
2026-08-31 (13d ago)
Active Installs
2,000+
Downloads
28,253
Requires WP
4.5+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2022-12-19 (4y ago)

Once the plugin is installed, you need to go to the integration section in the woocommerce settings and add the data delivered by blue express. Also, create a rest api user, this must be in the advanced options and deliver it to Blue Express for the correct functioning of the module.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C