Shopwell

Shopwell has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Shopwell has a vendor fix available, so running the current release closes it.

All of these findings were reported by Trương Hữu Phúc (truonghuuphuc). Shopwell is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Shopwell vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-25333

Shopwell <= 1.0.11 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Shopwell screenshot
Latestv1.0.19
4.5(2)
90/100
Last Updated
2026-08-13 (2d ago)
Active Installs
1,000+
Downloads
24,739
Requires WP
5.0+
Requires PHP
7.1+
Created
2025-04-30 (1y ago)

ShopWell is a fast, lightweight, and customizable WooCommerce theme for online stores and multivendor marketplaces. It offers mobile-first design, flexible layouts, sticky navigation, and customizable headers and footers. It supports popular page builders like Elementor, Gutenberg, Brizy, and Divi. Compatible with WCBoost – Wishlist, Compare, Variation Swatches, Dokan, WCFM, Contact Form 7, and MailChimp. The theme is SEO-friendly, WPML-compatible, and RTL-ready. Live preview: https://peregrine-themes.com/shopwell/#demos

Tags
BlogE commerceOne columnCustom logoCustom menuSticky postTwo columnsEditor styleLeft sidebarPost formatsCustom colorsRight sidebarTheme optionsFooter widgetsFeatured imagesThreaded commentsTranslation readyFull width templateRTL language support

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C