plugin

Shopbuilder Vulnerabilities

8 known security issues reported for the Shopbuilder WordPress plugin. Most recent disclosed Mar 13, 2026.

1 high 3 medium

Running Shopbuilder on your site? Check whether your installed version is affected.

Scan your site free

ShopBuilder &#8211; WooCommerce Builder For Elementor [shopbuilder] <= 3.2.4 (unfixed)

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Retrieve Embedded Sensitive Data.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through <= 3.2.4.

Affected:
up to 3.2.4
Fix:
No patched version reported
Disclosed:
Mar 13, 2026

CVE-2026-32372 on NVD →

ShopBuilder – Elementor WooCommerce Builder Addons <= 3.2.4 - Unauthenticated Information Exposure

medium

The ShopBuilder – WooCommerce Builder For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.4. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Feb 18, 2026

CVE-2026-32372 on NVD →

ShopBuilder &#8211; WooCommerce Builder For Elementor [shopbuilder] < 3.2.2

unknown

[en] The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Jan 2, 2026

CVE-2025-13456 on NVD →

Shopbuilder <= 3.2.1 - Reflected Cross-Site Scripting

medium

The Shopbuilder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...

CVSS:
6.1
Affected:
up to 3.2.1
Fixed in:
3.2.2
Disclosed:
Dec 12, 2025

CVE-2025-13456 on NVD →

ShopBuilder &#8211; WooCommerce Builder For Elementor [shopbuilder] < 2.1.13

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons allows Path Traversal.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through 2.1.12.

Affected:
up to 2.1.13
Fixed in:
2.1.13
Disclosed:
Jul 9, 2024

CVE-2024-37520 on NVD →

ShopBuilder – Elementor WooCommerce Builder Addons <= 2.1.12 - Authenticated (Contributor+) Local File Inclusion

high

The ShopBuilder – Elementor WooCommerce Builder Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.1.12. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the...

CVSS:
8.8
Affected:
up to 2.1.12
Fixed in:
2.1.13
Disclosed:
Jul 5, 2024

CVE-2024-37520 on NVD →

ShopBuilder &#8211; WooCommerce Builder For Elementor [shopbuilder] < 2.1.9

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through 2.1.8.

Affected:
up to 2.1.9
Fixed in:
2.1.9
Disclosed:
May 13, 2024

CVE-2024-34812 on NVD →

ShopBuilder – Elementor WooCommerce Builder Addons <= 2.1.8 - Unauthenticated Sensitive Information Exposure

medium

The ShopBuilder – Elementor WooCommerce Builder Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.1.8
Fixed in:
2.1.9
Disclosed:
May 9, 2024

CVE-2024-34812 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database