StoreKeeper for WooCommerce

StoreKeeper for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 0 high. 2025 was the busiest year with 2 disclosures.

The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 2 of the records (100%).

Every one of the 2 issues recorded for StoreKeeper for WooCommerce has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. StoreKeeper for WooCommerce is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all StoreKeeper for WooCommerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2025-48148

StoreKeeper for WooCommerce <= 14.4.4 - Unauthenticated Arbitrary File Upload

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv14.5.0

StoreKeeper for WooCommerce

StoreKeeper B.V.

Author

StoreKeeper B.V.

0.0(0)
0/100
Last Updated
2025-10-27 (11mo ago)
Active Installs
10+
Downloads
6,611
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 6.5.10
Created
2021-09-24 (5y ago)

This plugin provides sync possibilities with the StoreKeeper Backoffice. Allows synchronization of the WooCommerce product catalog, customers, orders and handles payments using StoreKeeper payment platform.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C