Product Author for WooCommerce

Product Author for WooCommerce has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.6, and the most serious one scores 6.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Missing Authorization.

Every one of the 3 issues recorded for Product Author for WooCommerce has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Product Author for WooCommerce is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.6/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Product Author for WooCommerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.3CVE-2022-4974

Freemius SDK <= 2.4.2 - Missing Authorization Checks

Read the full analysis

Vulnerability Records

3 records
Product Author for WooCommerce banner
Latestv2.0.1

Product Author for WooCommerce

Nitin Prakash

Author

Nitin Prakash

5.0(4)
100/100
Last Updated
2026-09-01 (12d ago)
Active Installs
500+
Downloads
14,106
Requires WP
6.2+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2019-03-10 (8y ago)

Product Author for WooCommerce is an open source plugin that allows admin to add Author to Woocommerce Product. This plugin enables author functionality for Woocommerce Products, Author can be assigned to Woocommerce Product using this plugin. This plugin is compatible with latest wordpress, latest woocommerce version, PHP 5.6.x, PHP 7.x, PHP 8.x and Gutenberg. Product Author for WooCommerce now lets you assign user roles as product authors. You can choose which roles are eligible to be added as authors to products. Check out the screenshots for a closer look. License This plugin is released under the GPLv2 or later. You can find the full license text in the LICENSE file included with this plugin. Support For support or any inquiries, please contact us at neebplugins@gmail.com or create a suppport request on our Support Page. Enjoy using the Product Author for WooCommerce plugin!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C