Browse all 51 CVE security advisories affecting woocommerce. AI-powered Chinese analysis, POCs, and references for each vulnerability.
WooCommerce is an open-source e-commerce plugin for WordPress, enabling merchants to build and manage online stores. Its widespread adoption has made it a frequent target for attackers, resulting in 47 recorded Common Vulnerabilities and Exposures. Historically, the software has been susceptible to critical flaw classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation. These vulnerabilities often stem from insufficient input validation or improper access controls within the plugin’s codebase. While the project maintains an active security team that regularly issues patches, the sheer volume of installed instances creates a large attack surface. Notable incidents have involved compromised admin accounts and data exfiltration, highlighting the risks associated with outdated versions. Users are strongly advised to keep the software updated to mitigate these persistent threats and ensure transactional integrity.
CVE-2026-87831
2026-09-17
CVE-2026-84024
2026-09-12
CVE-2026-80339
2026-09-09
CVE-2026-77693
2026-08-26
CVE-2026-2996
2026-08-23
CVE-2026-19728
2026-08-16
CVE-2026-16611
2026-08-15
CVE-2026-14182
2026-08-13
CVE-2026-18391
2026-08-12
CVE-2026-19089
2026-08-10
CVE-2026-17016
2026-08-10
CVE-2026-17012
2026-08-10
CVE-2026-15215
2026-08-07
CVE-2026-15214
2026-08-07
CVE-2026-16054
2026-08-06
Showing up to 20 recent security advisories. View all →
This page lists every published CVE security advisory associated with woocommerce. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.