plugin

Customize My Account For Woocommerce Vulnerabilities

10 known security issues reported for the Customize My Account For Woocommerce WordPress plugin. Most recent disclosed Jul 15, 2026.

7 medium

Running Customize My Account For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter

medium

The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

CVSS:
4.4
Affected:
up to 4.4.14
Fixed in:
4.5.0
Disclosed:
Jul 15, 2026

CVE-2026-15324 on NVD →

SysBasics Customize My Account for WooCommerce – Live My Account Customizer <= 4.3.9 - Reflected Cross-Site Scripting

medium

The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

CVSS:
6.1
Affected:
up to 4.3.9
Fixed in:
4.3.10
Disclosed:
Jul 1, 2026

CVE-2026-57358 on NVD →

SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

medium

The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_height, min_width, max_height,...

CVSS:
6.4
Affected:
up to 4.3.6
Fixed in:
4.3.7
Disclosed:
Jun 17, 2026

CVE-2026-12136 on NVD →

SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Site Scripting via 'tab' Parameter

medium

The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
6.1
Affected:
up to 4.3.6
Fixed in:
4.3.7
Disclosed:
Jun 17, 2026

CVE-2026-12137 on NVD →

SysBasics Customize My Account for WooCommerce [customize-my-account-for-woocommerce] < 2.9.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SysBasics Customize My Account for WooCommerce allows Reflected XSS. This issue affects Customize My Account for WooCommerce: from n/a through 2.8.22.

Affected:
up to 2.9.0
Fixed in:
2.9.0
Disclosed:
Feb 14, 2025

CVE-2025-24592 on NVD →

SysBasics Customize My Account for WooCommerce <= 2.8.22 - Reflected Cross-Site Scripting

medium

The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.8.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
6.1
Affected:
up to 2.8.22
Fixed in:
2.9.0
Disclosed:
Dec 21, 2024

CVE-2025-24592 on NVD →

SysBasics Customize My Account for WooCommerce <= 2.7.29 - Reflected Cross-Site Scripting via tab Parameter

medium

The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 2.7.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

CVSS:
6.1
Affected:
up to 2.7.29
Fixed in:
2.7.30
Disclosed:
Nov 9, 2024

CVE-2024-10837 on NVD →

SysBasics Customize My Account for WooCommerce [customize-my-account-for-woocommerce] < 2.7.30

unknown

[en] The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 2.7.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb...

Affected:
up to 2.7.30
Fixed in:
2.7.30
Disclosed:
Nov 9, 2024

CVE-2024-10837 on NVD →

SysBasics Customize My Account for WooCommerce [customize-my-account-for-woocommerce] < 1.8.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Customize My Account for WooCommerce: from n/a through 1.8.3.

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Mar 15, 2024

CVE-2023-51369 on NVD →

Customize My Account for WooCommerce <= 1.8.3 - Cross-Site Request Forgery via restore_my_account_tabs

medium

The Customize My Account for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.3. This is due to missing or incorrect nonce validation on the restore_my_account_tabs function. This makes it possible for unauthenticated attackers to restore account tabs vi...

CVSS:
4.3
Affected:
up to 1.8.3
Fixed in:
1.8.4
Disclosed:
Dec 26, 2023

CVE-2023-51369 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database