Shopwell
Shopwell has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Shopwell has a vendor fix available, so running the current release closes it.
All of these findings were reported by Trương Hữu Phúc (truonghuuphuc). Shopwell is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2026-25333Shopwell <= 1.0.11 - Missing Authorization
Read the full analysisVulnerability Records

Shopwell
Author
peregrinethemes
ShopWell is a fast, lightweight, and customizable WooCommerce theme for online stores and multivendor marketplaces. It offers mobile-first design, flexible layouts, sticky navigation, and customizable headers and footers. It supports popular page builders like Elementor, Gutenberg, Brizy, and Divi. Compatible with WCBoost – Wishlist, Compare, Variation Swatches, Dokan, WCFM, Contact Form 7, and MailChimp. The theme is SEO-friendly, WPML-compatible, and RTL-ready. Live preview: https://peregrine-themes.com/shopwell/#demos
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C