Shopwarden – Automated WooCommerce monitoring & testing
Shopwarden – Automated WooCommerce monitoring & testing has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Shopwarden – Automated WooCommerce monitoring & testing has a vendor fix available, so running the current release closes it.
All of these findings were reported by Brian Sans-Souci (liardom). Shopwarden – Automated WooCommerce monitoring & testing is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-13315Shopwarden – Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to Arbitrary Options Update
Read the full analysisVulnerability Records

Shopwarden – Automated WooCommerce monitoring & testing
Author
shopwarden
Shopwarden makes sure that your WooCommerce store is fully operational and you’re not losing out on orders. With a broad range of checks we make sure that every aspect of your shop is working correctly. We monitor your uptime, use robots to monitor all your important flows like the checkout, make sure your plugins are up-to-date & secure and more. This plugin allows Shopwarden to hook into your WooCommerce installation to monitor your plugins, make sure our test orders don’t show up in your order list and gather metrics. Pricing Shopwarden has a free plan so everybody can get some peace of mind. Our $29 Pro plan will allow you to fully and extensivly monitor every aspect of your store. Check out the full details here. Data sharing After you link your Shopwarden account with this plugin, the following data will be shared: – WordPress installation general info & plugin list – Order metadata (no personal data) – Product names & images (to select a product for checkout testing)
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C