XT Ajax Add To Cart for WooCommerce
XT Ajax Add To Cart for WooCommerce has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 3 are fixed as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 6.3 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Missing Authorization.
Every one of the 3 issues recorded for XT Ajax Add To Cart for WooCommerce has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. XT Ajax Add To Cart for WooCommerce is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2022-4974Freemius SDK <= 2.4.2 - Missing Authorization Checks
Read the full analysisVulnerability Records

XT Ajax Add To Cart for WooCommerce
Author
XplodedThemes
“XT Ajax Add To Cart for WooCommerce” allows users to add single products or variable products to the cart without the need to reload the entire site each time. It is one of those plugins for WooCommerce you need in your list. It comes with lots of loading spinner choices. Furthermore, it also has an add to cart redirection option. You can either redirect to the checkout or the cart page, or even a custom page. The plugin is totally free! It is also included and loaded by our other plugins: Floating Cart for WooCommerce Quick View for WooCommerce Variation Swatches for WooCommerce Demo https://demos.xplodedthemes.com/woo-ajax-add-to-cart/ Features Can be enabled for both the shop and single product pages. Set a loading spinner and a checkmark icon to your add to cart buttons. Option to redirect user to the Cart, Checkout or a Custom Page after adding to the cart. Translations English – default Note: All our plugins are localized / translatable by default. This is very important for all users worldwide. So please contribute your language to the plugin to make it even more useful.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C