WooCommerce

Explore WooCommerce vulnerabilities across all versions. Currently tracking 44 known vulnerabilities, including severity, impact, and patch status.

01234567891018.07.2013Today18.07.20136.1WooCommerce <= 2.0.12 - Self-Reflected Cross-Site Scripting CVSS 6.1 · 18.07.201317.10.20136.1WooCommerce <= 2.0.17 - Cross-Site Scripting CVSS 6.1 · 17.10.201315.09.20147.3WooCommerce <= 2.2.2 - Cross-Site Scripting via range Parameter CVSS 7.3 · 15.09.201417.09.20146.1WooCommerce <= 2.2.2 - Reflected Cross-Site Scripting CVSS 6.1 · 17.09.201429.01.20156.1WooCommerce <= 2.2.10 - Cross-Site Scripting CVSS 6.1 · 29.01.201513.03.20157.2WooCommerce <= 2.3.5 - Stored Cross-Site Scripting CVSS 7.2 · 13.03.201510.06.20157.5WooCommerce <= 2.3.10 - PHP Object Injection CVSS 7.5 · 10.06.201517.11.20155.5WooCommerce < 2.4.9 - Cross-site Scripting CVSS 5.5 · 17.11.201519.07.20166.4WooCommerce <= 2.6.2 - Stored Cross-Site Scripting CVSS 6.4 · 19.07.201626.07.20166.4WooCommerce <= 2.6.3 - Stored Cross-Site Scripting via REST-API CVSS 6.4 · 26.07.201607.12.20165.5WooCommerce <= 2.6.8 - Authenticated Stored Cross-Site Scripting CVSS 5.5 · 07.12.201616.11.20178.8WooCommerce <= 3.2.3 - Authenticated PHP Object Injection CVSS 8.8 · 16.11.201729.08.20186.6WooCommerce <= 3.4.4 - Authenticated PHP Object Injection CVSS 6.6 · 29.08.201806.11.20187.2WooCommerce <= 3.4.5 - WooCommerce File Deletion CVSS 7.2 · 06.11.201829.11.20185.5WooCommerce <= 3.5.1 - Authenticated Stored Cross-Site Scripting CVSS 5.5 · 29.11.201820.02.20196.1WooCommerce <= 3.5.4 - Stored Cross-Site Scripting CVSS 6.1 · 20.02.201902.07.20197.2WooCommerce <= 3.6.4 - Missing File Type Validation CVSS 7.2 · 02.07.20198.8WooCommerce <= 3.6.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting CVSS 8.8 · 02.07.201921.01.20205.3WooCommerce < 4.7.0 - Insecure Direct Object Reference via order_id Parameter CVSS 5.3 · 21.01.202005.05.20208.8WooCommerce <= 4.0.4 - Unauthorized Post Meta Creation/Modification CVSS 8.8 · 05.05.202022.06.20206.1WooCommerce <= 4.2.0 - Reflected Cross-Site Scripting CVSS 6.1 · 22.06.202005.11.20206.5WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation CVSS 6.5 · 05.11.202021.04.20214.8WooCommerce <= 5.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.8 · 21.04.202113.07.20218.8WooCommerce < 5.5 - Authenticated Blind SQL Injection CVSS 8.8 · 13.07.202122.02.20225.4WooCommerce <= 6.2.0 - Incorrect Authorization Checks on REST API Endpoints CVSS 5.4 · 22.02.20227.2WooCommerce <= 6.2.0 - Path Traversal via Tax Importer CVSS 7.2 · 22.02.202210.03.20224.3WooCommerce < 6.3.1 - Unauthorized Order Status Change CVSS 4.3 · 10.03.202210.04.20226.5WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Information Disclosure CVSS 6.5 · 10.04.202220.06.20225.5WooCommerce <= 6.5.1 - Authenticated (Admin+) HTML Injection CVSS 5.5 · 20.06.202211.09.20234.9WooCommerce <= 7.0.0 - Authenticated(Shop Manager+) Sensitive Information Exposure CVSS 4.9 · 11.09.20235.3WooCommerce <= 7.8.2 - Sensitive Information Exposure CVSS 5.3 · 11.09.202315.11.20236.4WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image alt Attribute CVSS 6.4 · 15.11.202305.01.20244.3WooCommerce <= 8.2.2 - Cross-Site Request Forgery CVSS 4.3 · 05.01.202412.01.20246.1WooCommerce < 8.4.0 - Reflected Cross-Site Scripting CVSS 6.1 · 12.01.202405.04.20244.3WooCommerce <= 8.5.2 - Cross-Site Request Forgery CVSS 4.3 · 05.04.202410.06.20246.1WooCommerce 8.8.0 - 8.9.2 - Reflected Cross-Site Scripting via Order Attribution CVSS 6.1 · 10.06.202427.06.20242.7WooCommerce <= 8.9.2 - Authenticated (Shop Manager+) Content Injection CVSS 2.7 · 27.06.202416.08.20244.4WooCommerce <= 9.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 16.08.202414.10.20245.3WooCommerce <= 9.0.2 - Unauthenticated HTML Injection CVSS 5.3 · 14.10.202412.03.20254.4WooCommerce <= 9.7.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting CVSS 4.4 · 12.03.202521.05.20256.1WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting CVSS 6.1 · 21.05.202529.10.20254.4WooCommerce <= 10.0.2 - Authenticated (Shop manager+) Stored Cross-Site Scripting CVSS 4.4 · 29.10.202522.12.20254.3WooCommerce <= 10.4.2 - Authenticated (Subscriber+) Information Exposure CVSS 4.3 · 22.12.202510.03.20264.3WooCommerce < 10.5.3 - Cross-Site Request Forgery CVSS 4.3 · 10.03.2026

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

44

Get automatic notifications for all WooCommerce vulnerabilities before they are exploited.

Vulnerability Records

44 records
2026-03-10 00:00CVE-2026-3589
4.3
Medium
oolongeyaYes
2025-12-22 00:00CVE-2025-15033
4.3
Medium
Peter StöckliYes
2025-10-29 00:00CVE-2025-49042
4.4
Medium
SavPhill (Savphill)Yes
2025-05-21 00:00CVE-2025-5062
6.1
Medium
Antonio Rocco SpataroYes
2025-03-12 00:00CVE-2025-26762
4.4
Medium
SavPhill (Savphill)Yes
2024-10-14 17:07CVE-2024-9944
5.3
Medium
dropYes
2024-08-16 00:00CVE-2024-39666
4.4
Medium
stealthcopterYes
2024-06-27 00:00CVE-2024-35777
2.7
Low
SavPhill (Savphill)Yes
2024-06-10 00:00CVE-2024-37297
6.1
Medium
AnonymousYes
2024-04-05 00:00CVE-2024-22155
4.3
Medium
Dhabaleshwar DasYes
Showing 1–10 of 44 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C