Kit (formerly ConvertKit) for WooCommerce
Kit (formerly ConvertKit) for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).
The one issue recorded for Kit (formerly ConvertKit) for WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nguyen Ba Khanh. Kit (formerly ConvertKit) for WooCommerce is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-57753Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 - Unauthenticated Information Exposure
Read the full analysisVulnerability Records

Kit (formerly ConvertKit) for WooCommerce
Author
nathanbarry
Kit makes it easy to capture more leads and sell more products by easily embedding email capture forms anywhere. This Plugin integrates WooCommerce with Kit, allowing customers and purchase data to be automatically sent to your Kit account. Full plugin documentation is located here. Configuration Configure the plugin by navigating to WooCommerce > Settings > in the WordPress Administration Menu, then click the Integration tab > Kit Enable the integration Enter your API Key and API Secret, clicking Save changes Choose the Subscription Form, Tag or Sequence to subscribe Customers to when they complete the WooCommerce Checkout Configure other settings as necessary, depending on your requirements (Optional) Configure which Sequence, Form or Tag to subscribe a Customer to when editing individual WooCommerce Products
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C