Shipping by Weight for WooCommerce

Shipping by Weight for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.

Every one of the 2 issues recorded for Shipping by Weight for WooCommerce has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Shipping by Weight for WooCommerce is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
5.2/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Shipping by Weight for WooCommerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-32535

DN Shipping by Weight for WooCommerce <= 1.2 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Shipping by Weight for WooCommerce banner
Latestv1.2.2

Shipping by Weight for WooCommerce

digireturn

Author

digireturn

3.5(2)
70/100
Last Updated
2025-02-10 (2y ago)
Active Installs
50+
Downloads
2,886
Requires WP
5.0+
Requires PHP
5.6+
Tested up to
WP 6.7.7
Created
2020-11-23 (6y ago)

Manage shipping costs based on the total weight of the products in the cart. Available in English, Italian, Spanish and French It’s possible create various tables, with custom costs and link them to shipping zones to generate one precise and flexible mapping. It is possible to set a weight range from a determined number to infinity It is possible to set an incremental step, so that the cost increases by xx every yy kg (New) It is possible to set a custom message for each shipping zone. Create a table (go to the Woocommerce menu > DN Shipping by Weight) clicking the “Add new table” button, provide an identification name (not visible to users) and enter varius bands of price based on minimum weight and maximum weight (use points for decimal separator and no symbols for the thousands separator). Set up a shipping area (in the woocomerce settings menu -> shipping) and add the “weight-based” method. After you configure it using the “edit” button and select the desired table. In the same area also add a method to manage the eventual case where none rule of the selected table match the conditions (for example “pick up on site”) There is also a function for checking the weight of the products, where it will be possible to view the list of products to which the weight has not been assigned or has a zero value. ATTENTION: before activating the weight-based method make sure that all products have the field weight correctly set (also for variable products, etc.). The author not assumes responsibility of any anomalies generated. Verify and perform all appropriate tests first to use it in the production environment.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C