Flutterwave WooCommerce

Flutterwave WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Flutterwave WooCommerce has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by Jakub Herman. Flutterwave WooCommerce is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.0.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Flutterwave WooCommerce vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2026-73399

Flutterwave WooCommerce <= 3.3.0 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Flutterwave WooCommerce banner
Latestv3.3.0

Flutterwave WooCommerce

flutterwave

Author

flutterwave

2.5(11)
50/100
Last Updated
2026-07-27 (29d ago)
Active Installs
2,000+
Downloads
184,890
Requires WP
5.6+
Requires PHP
7.4+
Tested up to
WP 7.0.0
Created
2018-05-22 (8y ago)

Accept Credit card, Debit card and Bank account payment directly on your store with the official Flutterwave Plugin for WooCommerce. This plugin supports WooCommerce Version 6.9 or greater. For WooCommerce Version 6.8 or lower please install Flutterwave WooCommerce Version (2.3.6 or lower) of the plugin here at the section update advanced options. Plugin Features Collections: Card, Account, Mobile money, Bank Transfers, USSD, Barter, 1voucher. Recurring payments: Tokenization and Subscriptions. Split payments: Split payments between multiple recipients. Requirements Flutterwave for business API Keys WooCommerce version: >= 6.9 Supported PHP version: 7.4.0 – 8.1.0

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C