Meta for WooCommerce <= 3.7.5 - Unauthenticated Stored Cross-Site Scripting
high
The Meta for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user a...
- CVSS:
- 7.2
- Affected:
- up to 3.7.5
- Fixed in:
- 3.7.6
- Disclosed:
- Jul 31, 2026
CVE-2026-66707 on NVD →
Meta for WooCommerce <= 3.7.0 - Unauthenticated Open Redirect
medium
The Meta for WooCommerce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.7.0. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully tric...
- CVSS:
- 4.7
- Affected:
- up to 3.7.0
- Fixed in:
- 3.7.1
- Disclosed:
- May 27, 2026
CVE-2026-49059 on NVD →
Facebook for WooCommerce <= 3.5.7 - Missing Authorization to Unauthenticated Notification Dismissal
medium
The Facebook for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in versions up to, and including, 3.5.7. This makes it possible for unauthenticated attackers to dismiss notices.
- CVSS:
- 5.3
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.8
- Disclosed:
- Oct 29, 2025
CVE-2025-64296 on NVD →
Facebook for WooCommerce [facebook-for-woocommerce] < 1.9.15
unknown
[en] The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
- Affected:
- up to 1.9.15
- Fixed in:
- 1.9.15
- Disclosed:
- Aug 30, 2019
CVE-2019-15840 on NVD →
Facebook for WooCommerce [facebook-for-woocommerce] < 1.9.15
unknown
[en] The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
- Affected:
- up to 1.9.15
- Fixed in:
- 1.9.15
- Disclosed:
- Aug 30, 2019
CVE-2019-15841 on NVD →
Facebook for WooCommerce [facebook-for-woocommerce] < 1.9.14
unknown
Cross-Site Request Forgery (CSRF) vulnerability allowing Option Update found in WordPress Facebook for WooCommerce plugin (versions <= 1.9.12).
- Affected:
- up to 1.9.14
- Fixed in:
- 1.9.14
- Disclosed:
- Jun 25, 2019
Facebook for WooCommerce <= 1.9.12 - Cross-Site Request Forgery
high
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
- CVSS:
- 8.8
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.15
- Disclosed:
- Jun 18, 2019
CVE-2019-15840 on NVD →
Facebook for WooCommerce <= 1.9.12 - Cross-Site Request Forgery allowing Option Update
high
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
- CVSS:
- 8.8
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.15
- Disclosed:
- Jun 18, 2019
CVE-2019-15841 on NVD →
Facebook for WooCommerce [facebook-for-woocommerce] < 3.5.8
unknown
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.8
CVE-2025-64296 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database