External Store for Shopify
External Store for Shopify has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include PHP Remote File Inclusion.
Every one of the 2 issues recorded for External Store for Shopify has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. External Store for Shopify is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-30999WP Shopify <= 1.5.9 - Authenticated (Contributor+) Local File Inclusion
Read the full analysisVulnerability Records

External Store for Shopify
Author
Fahad Mahmood
Display Shopify products on your WordPress blog. How it works? A) Set up all the apis as directed by the App B) Set up two new pages on your WordPress website Page #1 Set the permalink to shopify (or products, shop, catalogue etc.) and add code [wp-shopify type=”products” limit=”100″ url-type=”default”] Page #2 Set the permalink to product (note there is no “s” at the end of the product in the url, the slug/permalink should be with exactly “product”) and insert code [wp-shopify-product] (this is where product redirect link to shopify store will work on your WordPress website) C) Modify the layout of your WordPress website pages with the CSS
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C