Plugin BlueX for WooCommerce
Plugin BlueX for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Plugin BlueX for WooCommerce has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by NumeX. Plugin BlueX for WooCommerce is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-68022Plugin BlueX for WooCommerce <= 3.1.4 - Missing Authorization
Read the full analysisVulnerability Records
Plugin BlueX for WooCommerce
Author
soporteblue
Once the plugin is installed, you need to go to the integration section in the woocommerce settings and add the data delivered by blue express. Also, create a rest api user, this must be in the advanced options and deliver it to Blue Express for the correct functioning of the module.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C