Stock Locations for WooCommerce
Stock Locations for WooCommerce has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.4 out of 10.
The most common weakness is Missing Authorization, behind 2 of the records (67%). Other recurring categories include Cross-Site Scripting.
Every one of the 3 issues recorded for Stock Locations for WooCommerce has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Stock Locations for WooCommerce is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-22153Stock Locations for WooCommerce <= 2.5.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
Read the full analysisVulnerability Records

Stock Locations for WooCommerce
Author
Fahad Mahmood
Stock Locations for WooCommerce will help you manage your products stock across multiple locations easily. If you have multiple physical stores or storage locations, like warehouses, this plugin may help you. You can print the locations inside a product page on the frontend, with this shortcodes: Product pages [slw_product_locations show_qty="yes" show_stock_status="no" show_empty_stock="yes" collapsed="no" stock_location_status="enabled"] [slw_product_variations_locations show_qty="yes" show_stock_status="no" show_empty_stock="yes" collapsed="yes" stock_location_status="all|disabled|enabled"] [slw_product_message is_available="yes" only_location_available="no" location="location-slug"]Your custom product message/HTML here[/slw_product_message] Cart page [slw_cart_message qty_from_location="location-slug" only_location_available="no"]Your custom cart message/HTML here[/slw_cart_message] REST API REST API endpoints (both accept GET and PUT requests): /wp-json/wc/v3/products/id /wp-json/wc/v3/products/id/variations/id (first ID is for parent product, the second one for the variation ID) /wp-json/wp/v2/location/ /wp-json/wp/v2/location/id This plugin requires at least WooCommerce 3.4. Features New taxonomy for stock locations Works on both, simple and variable products Easy management of stock with multiple locations, both in product and orders Get and update product stock locations from the REST API Allow customers to select locations when purchasing Auto order allocation for locations stock reduction Send email notifications when stock is allocated for a product in a location Send WooCommerce New Order email copy to item location Compatible with WPML Compatibility PHP 7.2+
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C