Cart tracking for WooCommerce
Cart tracking for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 4.9, and the most serious one scores 4.9 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is SQL Injection, behind 2 of the records (100%).
Every one of the 2 issues recorded for Cart tracking for WooCommerce has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Cart tracking for WooCommerce is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-47538Cart tracking for WooCommerce <= 1.0.17 - Authenticated (Administrator+) SQL Injection
Read the full analysisVulnerability Records
Cart tracking for WooCommerce
Author
wpdever
This plugin gives you a better insight into what people are adding or removing to/from their cart. You can see all recorded carts in a table, as well as which products were added or removed most often. Comparing cart data with your sales data can be helpful in understanding what your customers want. Seeing actively removed products can also help you increase your sales by giving you the possibility to offer discounts for these products as an example. Knowing what’s happening on the customers side can be valuable in making data-informed decisions to boost your sales. This plugin records customers carts as long as it’s activated. Pro Features Available Most added and removed products lists twice longer User cart detailed history, with every event recorded User cart and order data (most added/purchased product, total carts, total orders, total orders completed, on hold, cancelled….)
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C