Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Booster for WooCommerce — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Booster for WooCommerce, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses associated with Booster for WooCommerce, a popular plugin for the WordPress e-commerce platform. It aggregates vulnerability data categorized by vendor, specific product components, and common weakness enumeration types to provide a centralized reference for security researchers and administrators. The collection includes reported security issues affecting this software, covering incidents identified and disclosed over a multi-year period up to the most recent updates. By reviewing this aggregated information, users can efficiently track vendor security advisories as they are issued, gaining insight into how the developer handles critical flaws. Readers can also analyze specific weakness classes to understand the technical nature of the flaws, such as cross-site scripting or privilege escalation errors, and evaluate their potential impact. Furthermore, the page allows for a detailed lookup of the product’s vulnerability history, offering a chronological view of past issues and their resolution status. This historical context helps stakeholders assess the overall security posture of the software over time and prioritize patching efforts. The data is compiled to support transparent security reporting and to aid in the maintenance of secure WordPress environments. By providing a clear overview of known defects, this resource supports informed decision-making for site owners who rely on Booster for WooCommerce to manage their online stores, ensuring that potential risks are recognized and mitigated effectively.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-56027 WordPress Booster for WooCommerce plugin <= 8.0.1 - Arbitrary File Upload vulnerability CWE-434 9.9 Critical 2026-06-26
CVE-2026-32586 WordPress Booster for WooCommerce plugin < 7.11.3 - Broken Access Control vulnerability CWE-862 5.3 Medium 2026-03-17
CVE-2025-64380 WordPress Booster for WooCommerce plugin <= 7.3.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-11-13
CVE-2025-64379 WordPress Booster for WooCommerce plugin <= 7.4.0 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-11-13
CVE-2025-64196 WordPress Booster for WooCommerce plugin <= 7.2.5 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-11-06
CVE-2024-13708 Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Stored Cross-Site Scripting CWE-434 7.2 High 2025-04-04
CVE-2024-13744 Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Arbitrary File Upload CWE-434 8.1 High 2025-04-04
CVE-2023-48747 WordPress Booster for WooCommerce plugin <= 7.1.2 - Authenticated Production Creation/Modification Vulnerability CWE-287 6.5 Medium 2024-06-04
CVE-2024-29760 WordPress Booster for WooCommerce plugin <= 7.1.8 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-03-27
CVE-2023-48333 WordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data Exposure CWE-200 6.5 Medium 2023-11-30
CVE-2023-40002 WordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data Exposure CWE-200 6.5 Medium 2023-11-22
CVE-2022-4017 Booster for WooCommerce - Multiple CSRF 8.8 - 2023-01-23
CVE-2022-4227 Booster for WooCommerce - Reflected Cross-Site Scripting 6.1 - 2022-12-26
CVE-2022-4016 Booster for WooCommerce - Custom Role Creation/Deletion via CSRF 6.5 - 2022-12-12
CVE-2022-3763 Booster for WooCommerce - Checkout Files Deletion via CSRF 6.5 - 2022-11-21
CVE-2022-3762 Booster for WooCommerce - ShopManager+ Arbitrary File Download 7.5 - 2022-11-21
CVE-2021-25001 Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in Product XML Feeds Module CWE-79 6.1 - 2022-01-03
CVE-2021-25000 Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in General Module CWE-79 6.1 - 2022-01-03
CVE-2021-24999 Booster for Woocommerce < 5.4.9 - Reflected Cross-Site Scripting in PDF Invoicing Module CWE-79 6.1 - 2022-01-03

All 19 known CVE vulnerabilities affecting Booster for WooCommerce with full Chinese analysis, references, and POCs where available.