Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

woocommerce — Vulnerabilities & Security Advisories 51

Browse all 51 CVE security advisories affecting woocommerce. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WooCommerce is an open-source e-commerce plugin for WordPress, enabling merchants to build and manage online stores. Its widespread adoption has made it a frequent target for attackers, resulting in 47 recorded Common Vulnerabilities and Exposures. Historically, the software has been susceptible to critical flaw classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation. These vulnerabilities often stem from insufficient input validation or improper access controls within the plugin’s codebase. While the project maintains an active security team that regularly issues patches, the sheer volume of installed instances creates a large attack surface. Notable incidents have involved compromised admin accounts and data exfiltration, highlighting the risks associated with outdated versions. Users are strongly advised to keep the software updated to mitigate these persistent threats and ensure transactional integrity.

Found 2 results / 51 Clear Filters
High 2026-09-28
Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauthenticated Blind Server-Side Request Forgery
High 2026-09-28
Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via
Medium CVE-2026-87831 2026-09-17
Checkout Field Manager < 7.9.7 – Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field | CVE 2026-
Medium CVE-2026-84024 2026-09-12
BEAR – Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 – Meta Field Configuration Update via CSRF
High 2026-09-09
Checkout Custom Fields Builder for WooCommerce <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary
Medium CVE-2026-80339 2026-09-09
Payment Plugins for Stripe WooCommerce < 4.0.12 – Unauthenticated Customer PII Disclosure via order-pay | CVE 2026-80339
Medium 2026-09-09
Product Filter for WooCommerce by WBW <= 3.4.2 - Reflected Cross-Site Scripting via 'wpf_fid' Parameter
High CVE-2026-77693 2026-08-26
Order Tip for WooCommerce < 1.6.0 – Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajax | CVE 2026-7
Critical 2026-08-25
eCommerce Product Catalog <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Att
High CVE-2026-2996 2026-08-23
Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.21 - Unauthenticated Improper Input Validation to Price
Low CVE-2026-19728 2026-08-16
Extra Product Options Builder for WooCommerce < 1.2.176 – Unauthenticated Customer File Disclosure via getpublicfileuplo
Medium CVE-2026-16611 2026-08-15
Product Feed PRO for WooCommerce < 13.5.7 – Unauthenticated Feed Configuration Disclosure | CVE 2026-16611 | Plugin Vuln
Critical CVE-2026-14182 2026-08-13
Customer Email Verification for WooCommerce < 3.2.6 – Unauthenticated Account Takeover via Type-Juggling Authentication
Critical CVE-2026-18391 2026-08-12
WooCommerce Subscriptions < 9.1.0 – Unauthenticated RCE via PHP Object Injection | CVE 2026-18391 | Plugin Vulnerabiliti
Critical CVE-2026-19089 2026-08-10
Product Input Fields for WooCommerce < 2.0.2 – Unauthenticated Arbitrary File Upload | CVE 2026-19089 | Plugin Vulnerabi
Low CVE-2026-17016 2026-08-10
Restore PayPal Standard for WooCommerce <= 3.1.0 – Payment Bypass via PDT Underpayment | CVE 2026-17016 | Plugin Vulnera
Medium CVE-2026-17012 2026-08-10
Restore PayPal Standard for WooCommerce <= 3.1.0 – Payment Bypass via Unvalidated receiver_email | CVE 2026-17012 | Plug
High CVE-2026-15215 2026-08-07
Subscriptions for WooCommerce < 2.0.1 – Shop Manager+ Arbitrary Plugin Installation | CVE 2026-15215 | Plugin Vulnerabil
Medium CVE-2026-15214 2026-08-07
Subscriptions for WooCommerce < 2.0.1 – Subscriber+ Subscription Detail Disclosure via IDOR | CVE 2026-15214 | Plugin Vu
Medium CVE-2026-16054 2026-08-06
Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 – Unauthenticated File Deletion via Nonce Oracle | CVE 2026-1

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with woocommerce. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.