Revamp CRM for WooCommerce
Revamp CRM for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 8.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include PHP Remote File Inclusion.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
All of these findings were reported by thiennv. Revamp CRM for WooCommerce is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2025-32512Revamp CRM for WooCommerce <= 1.1.2 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Revamp CRM for WooCommerce
Author
revampcrm
Revamp CRM for WooCommerce is a free plugin that connects your WooCommerce store with your Revamp CRM account. Your products, customers and their purchase data are automatically synced with Revamp CRM, so you can segment them, automate actions based on their buying behavior Or send out newsletters to them. You’ll have the power to: Sync list and purchase data Create abandoned cart Automation workflows Send product recommendations Segment based on purchase history View your results and measure ROI Grow your audience and sell more stuff with Facebook Ad Campaigns in Revamp CRM
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C