plugin

Woocommerce Vulnerabilities

140 known security issues reported for the Woocommerce WordPress plugin. Most recent disclosed Mar 10, 2026.

10 high 34 medium 1 low

Running Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce - Arbitrary Admin User Creation via CSRF vulnerability

medium

Arbitrary Admin User Creation via CSRF vulnerability

CVSS:
4.3
Affected:
up to 10.5.3
Fixed in:
10.5.3
Disclosed:
Mar 10, 2026

WooCommerce < 10.5.3 - Cross-Site Request Forgery

medium

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 10.5.3 (exclusive). This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrato...

CVSS:
4.3
Affected:
up to 10.5.3
Fixed in:
10.5.3
Disclosed:
Mar 10, 2026

CVE-2026-3589 on NVD →

WooCommerce <= 10.4.2 - Authenticated (Subscriber+) Information Exposure

medium

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.4.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
10.0 – 10.0.4, 10.1 – 10.1.2, 10.2 – 10.2.2, 10.3 – 10.3.6, 8.1 – 8.1.2, 8.2 – 8.2.3, 8.3 – 8.3.2, 8.4 – 8.4.1, 8.5 – 8.5.3, 8.6 – 8.6.2, 8.7 – 8.7.1, 8.8 – 8.8.5, 8.9 – 8.9.3, 9.0 – 9.0.2, 9.1 – 9.1.4, 9.2 – 9.2.3, 9.3 – 9.3.4, 9.4 – 9.4.3, 9.5 – 9.5.2, 9.6 – 9.6.2, 9.7 – 9.7.1, 9.8 – 9.8.5, 9.9 – 9.9.5
Fixed in:
10.0.5
Disclosed:
Dec 22, 2025

CVE-2025-15033 on NVD →

WooCommerce [woocommerce] < 10.4.3

unknown

[en] A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it has been fixed in...

Affected:
up to 10.4.3
Fixed in:
10.4.3
Disclosed:
Dec 22, 2025

CVE-2025-15033 on NVD →

WooCommerce <= 10.0.2 - Authenticated (Shop manager+) Stored Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
4.4
Affected:
up to 10.0.2
Fixed in:
10.0.3
Disclosed:
Oct 29, 2025

CVE-2025-49042 on NVD →

WooCommerce [woocommerce] <= 10.0.2 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through 10.0.2.

Affected:
up to 10.0.2
Fix:
No patched version reported
Disclosed:
Oct 29, 2025

CVE-2025-49042 on NVD →

WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. This makes it possible for unauthenticated attackers to inject arbitrary...

CVSS:
6.1
Affected:
up to 9.3.2, 9.4 – 9.4.2
Fixed in:
9.3.4
Disclosed:
May 21, 2025

CVE-2025-5062 on NVD →

WooCommerce [woocommerce] < 9.7.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce allows Stored XSS.This issue affects WooCommerce: from n/a through 9.7.0.

Affected:
up to 9.7.1
Fixed in:
9.7.1
Disclosed:
Mar 27, 2025

CVE-2025-26762 on NVD →

WooCommerce <= 9.7.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level permissions and above, to inject arbitr...

CVSS:
4.4
Affected:
up to 9.7.0
Fixed in:
9.7.1
Disclosed:
Mar 12, 2025

CVE-2025-26762 on NVD →

WooCommerce [woocommerce] < 9.4.3

unknown

<p>WordPress WooCommerce Plugin < 9.4.3 is vulnerable to Broken Access Control</p><p>Software: WooCommerce</p><p>Fixed in version 9.4.3 </p><p>Affected Version < 9.4.3</p>

Affected:
up to 9.4.3
Fixed in:
9.4.3
Disclosed:
Dec 4, 2024

WooCommerce [woocommerce] < 9.1.0

unknown

[en] The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the adm...

Affected:
up to 9.1.0
Fixed in:
9.1.0
Disclosed:
Oct 15, 2024

CVE-2024-9944 on NVD →

WooCommerce <= 9.0.2 - Unauthenticated HTML Injection

medium

The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administ...

CVSS:
5.3
Affected:
up to 9.0.2
Fixed in:
9.1.0
Disclosed:
Oct 14, 2024

CVE-2024-9944 on NVD →

WooCommerce [woocommerce] < 9.1.3

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 9.1.2.

Affected:
up to 9.1.3
Fixed in:
9.1.3
Disclosed:
Aug 18, 2024

CVE-2024-39666 on NVD →

WooCommerce <= 9.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
4.4
Affected:
up to 9.1.2
Fixed in:
9.1.3
Disclosed:
Aug 16, 2024

CVE-2024-39666 on NVD →

WooCommerce [woocommerce] < 9.0.0

unknown

[en] Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a through 8.9.2.

Affected:
up to 9.0.0
Fixed in:
9.0.0
Disclosed:
Jul 9, 2024

CVE-2024-35777 on NVD →

WooCommerce <= 8.9.2 - Authenticated (Shop Manager+) Content Injection

low

The WooCommerce plugin for WordPress is vulnerable to content injection in all versions up to, and including, 8.9.2. This is due to the plugin not properly restricting/validating content. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inject arbitrary content.

CVSS:
2.7
Affected:
up to 8.9.2
Fixed in:
9.0.0
Disclosed:
Jun 27, 2024

CVE-2024-35777 on NVD →

WooCommerce [woocommerce] < 8.9.3

unknown

[en] WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While the content is not saved to the database, the links may be sent to victims for...

Affected:
up to 8.9.3
Fixed in:
8.9.3
Disclosed:
Jun 12, 2024

CVE-2024-37297 on NVD →

WooCommerce [woocommerce] < 8.9.3

unknown

<p>WordPress WooCommerce Plugin <= 8.9.2 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: WooCommerce</p><p>Link: https://wordpress.org/plugins/woocommerce/#developers</p><p>Affected Version <= 8.9.2</p><p>Fixed in version 8.9.3 </p>

Affected:
up to 8.9.3
Fixed in:
8.9.3
Disclosed:
Jun 11, 2024

WooCommerce 8.8.0 - 8.9.2 - Reflected Cross-Site Scripting via Order Attribution

medium

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via order attribution cookies in versions 8.8.0 to 8.8.4 and 8.9.0 to 8.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
8.8.0 – 8.8.4, 8.9.0 – 8.9.2
Fixed in:
8.8.5
Disclosed:
Jun 10, 2024

CVE-2024-37297 on NVD →

WooCommerce [woocommerce] < 8.6

unknown

[en] The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

Affected:
up to 8.6
Fixed in:
8.6
Disclosed:
Apr 15, 2024

CVE-2024-1310 on NVD →

WooCommerce [woocommerce] < 8.6.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2.

Affected:
up to 8.6.0
Fixed in:
8.6.0
Disclosed:
Apr 7, 2024

CVE-2024-22155 on NVD →

WooCommerce <= 8.5.2 - Cross-Site Request Forgery

medium

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 8.5.2
Fixed in:
8.6.0
Disclosed:
Apr 5, 2024

CVE-2024-22155 on NVD →

WooCommerce [woocommerce] < 6.2.1

unknown

[en] The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment

Affected:
up to 6.2.1
Fixed in:
6.2.1
Disclosed:
Jan 16, 2024

CVE-2022-0775 on NVD →

WooCommerce < 8.4.0 - Reflected Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions before 8.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user i...

CVSS:
6.1
Affected:
up to 8.4.0
Fixed in:
8.4.0
Disclosed:
Jan 12, 2024

WooCommerce [woocommerce] < 8.4.0

unknown

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions before 8.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user i...

Affected:
up to 8.4.0
Fixed in:
8.4.0
Disclosed:
Jan 12, 2024

WooCommerce [woocommerce] < 8.3.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.

Affected:
up to 8.3.0
Fixed in:
8.3.0
Disclosed:
Jan 8, 2024

CVE-2023-52222 on NVD →

WooCommerce <= 8.2.2 - Cross-Site Request Forgery

medium

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 8.2.2
Fixed in:
8.3.0
Disclosed:
Jan 5, 2024

CVE-2023-52222 on NVD →

WooCommerce [woocommerce] < 8.2.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.

Affected:
up to 8.2.0
Fixed in:
8.2.0
Disclosed:
Nov 30, 2023

CVE-2023-47777 on NVD →

WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image alt Attribute

medium

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a featured image 'alt' attribute in versions up to, and including, 8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...

CVSS:
6.4
Affected:
up to 8.1.1
Fixed in:
8.2.0
Disclosed:
Nov 15, 2023

CVE-2023-47777 on NVD →

WooCommerce <= 7.8.2 - Sensitive Information Exposure

medium

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information in...

CVSS:
5.3
Affected:
up to 7.8.2
Fixed in:
7.9.0
Disclosed:
Sep 11, 2023

CVE-2023-7320 on NVD →

WooCommerce <= 7.0.0 - Authenticated(Shop Manager+) Sensitive Information Exposure

medium

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.0. This can allow authenticated attackers with Shop Manager privileges or above to extract sensitive user metadata including session tokens.

CVSS:
4.9
Affected:
up to 7.0.0
Fixed in:
7.0.1
Disclosed:
Sep 11, 2023

WooCommerce [woocommerce] < 7.0.1

unknown

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.0. This can allow authenticated attackers with Shop Manager privileges or above to extract sensitive user metadata including session tokens.

Affected:
up to 7.0.1
Fixed in:
7.0.1
Disclosed:
Sep 11, 2023

WooCommerce [woocommerce] < 7.9.0

unknown

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information in...

Affected:
up to 7.9.0
Fixed in:
7.9.0
Disclosed:
Sep 11, 2023

WooCommerce [woocommerce] < 6.6.0

unknown

[en] The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

Affected:
up to 6.6.0
Fixed in:
6.6.0
Disclosed:
Jul 17, 2022

CVE-2022-2099 on NVD →

WooCommerce <= 6.5.1 - Authenticated (Admin+) HTML Injection

medium

The WooCommerce plugin for WordPress is vulnerable to Stored HTML Injection via payment gateway titles in versions up to 6.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with high-level capabilities, such as a Store Manager, to inject arbitrary web scr...

CVSS:
5.5
Affected:
up to 6.6.0
Fixed in:
6.6.0
Disclosed:
Jun 20, 2022

CVE-2022-2099 on NVD →

WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Information Disclosure

medium

The WooCommerce and WooCommerce Admin plugins for WordPress are vulnerable to Sensitive Data Exposure in versions up to 5.7.0 for WooCommerce and 2.6.4 for WooCommerce Admin due to insufficient protection of analytic report storage in the directory they are stored. This makes it possible for attackers to extract sensit...

CVSS:
6.5
Affected:
up to 4.0, 4.0 – 4.0.3, 4.1 – 4.1.3, 4.2 – 4.2.4, 4.3 – 4.3.5, 4.4 – 4.4.3, 4.5 – 4.5.4, 4.6 – 4.6.4, 4.7 – 4.7.3, 4.8 – 4.8.2, 4.9 – 4.9.4, 5.0 – 5.0.2, 5.1 – 5.1.2, 5.2 – 5.2.4, 5.3 – 5.3.2, 5.4 – 5.4.3, 5.5 – 5.5.3, 5.6 – 5.6.1
Fixed in:
4.0.3
Disclosed:
Apr 10, 2022

WooCommerce [woocommerce] < 5.7.0

unknown

The WooCommerce and WooCommerce Admin plugins for WordPress are vulnerable to Sensitive Data Exposure in versions up to 5.7.0 for WooCommerce and 2.6.4 for WooCommerce Admin due to insufficient protection of analytic report storage in the directory they are stored. This makes it possible for attackers to extract sensit...

Affected:
up to 5.7.0
Fixed in:
5.7.0
Disclosed:
Apr 10, 2022

WooCommerce < 6.3.1 - Unauthorized Order Status Change

medium

The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce check on the PayPal order updates functionality in versions up to, and including, 6.3.0. This makes it possible for authenticated attackers to change the status of arbitrary orders that have been creat...

CVSS:
4.3
Affected:
3.5 – 3.5.10, 3.6 – 3.6.7, 3.7 – 3.7.3, 3.8 – 3.8.3, 3.9 – 3.9.5, 4.0 – 4.0.4, 4.1 – 4.1.4, 4.2 – 4.2.5, 4.3 – 4.3.6, 4.4 – 4.4.4, 4.5 – 4.5.5, 4.6 – 4.6.5, 4.7 – 4.7.4, 4.8 – 4.8.3, 4.9 – 4.9.5, 5.0 – 5.0.3, 5.1 – 5.1.3, 5.2 – 5.2.5, 5.3 – 5.3.3, 5.4 – 5.4.4, 5.5 – 5.5.4, 5.6 – 5.6.2, 5.7 – 5.7.2, 5.8 – 5.8.1, 5.9 – 5.9.1, 6.0 – 6.0.1, 6.1 – 6.1.2, 6.2 – 6.2.2, 6.3 – 6.3.1
Fixed in:
3.5.10
Disclosed:
Mar 10, 2022

WooCommerce [woocommerce] < 6.3.1

unknown

Orders Status Change (via PayPal Standard Gateway) vulnerability discovered in WordPress WooCommerce plugin (versions <= 6.3.0).

Affected:
up to 6.3.1
Fixed in:
6.3.1
Disclosed:
Mar 10, 2022

WooCommerce [woocommerce] < 6.3.1

unknown

The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce check on the PayPal order updates functionality in versions up to, and including, 6.3.0. This makes it possible for authenticated attackers to change the status of arbitrary orders that have been creat...

Affected:
up to 6.3.1
Fixed in:
6.3.1
Disclosed:
Mar 10, 2022

WooCommerce [woocommerce] < 6.2.1

unknown

Path Traversal via Importers vulnerability discovered in WordPress WooCommerce plugin (versions <= 6.2.0).

Affected:
up to 6.2.1
Fixed in:
6.2.1
Disclosed:
Feb 23, 2022

WooCommerce [woocommerce] < 6.2.1

unknown

Arbitrary Comment Deletion vulnerability discovered in WordPress WooCommerce plugin (versions <= 6.2.0).

Affected:
up to 6.2.1
Fixed in:
6.2.1
Disclosed:
Feb 23, 2022

WooCommerce <= 6.2.0 - Path Traversal via Tax Importer

high

The WooCommerce plugin for WordPress is vulnerable to path traversal via the 'file_url' parameter found in the importers functionality in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers, with high-level permissions such as an administrator, to access files outside of the intende...

CVSS:
7.2
Affected:
up to 6.2.0
Fixed in:
6.2.1
Disclosed:
Feb 22, 2022

WooCommerce <= 6.2.0 - Incorrect Authorization Checks on REST API Endpoints

medium

The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on the /wc/v2/products/ REST API in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers with minimal permissions such as a subscriber to delete, edit, and read arbitrar...

CVSS:
5.4
Affected:
up to 6.2.0
Fixed in:
6.2.1
Disclosed:
Feb 22, 2022

CVE-2022-0775 on NVD →

WooCommerce [woocommerce] < 6.2.1

unknown

The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on the /wc/v2/products/ REST API in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers with minimal permissions such as a subscriber to delete, edit, and read arbitrar...

Affected:
up to 6.2.1
Fixed in:
6.2.1
Disclosed:
Feb 22, 2022

WooCommerce [woocommerce] < 6.2.1

unknown

The WooCommerce plugin for WordPress is vulnerable to path traversal via the 'file_url' parameter found in the importers functionality in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers, with high-level permissions such as an administrator, to access files outside of the intende...

Affected:
up to 6.2.1
Fixed in:
6.2.1
Disclosed:
Feb 22, 2022

WooCommerce [woocommerce] < 5.7.0

unknown

Analytics Report Leaks vulnerability discovered in the WordPress WooCommerce plugin (versions <= 5.6.0).

Affected:
up to 5.7.0
Fixed in:
5.7.0
Disclosed:
Sep 22, 2021

WooCommerce [woocommerce] < 6.6.0

unknown

[en] Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `/wp-jso...

Affected:
up to 6.6.0
Fixed in:
6.6.0
Disclosed:
Jul 26, 2021

CVE-2021-32790 on NVD →

WooCommerce [woocommerce] < 5.5.1

unknown

Unauthenticated SQL Injection (SQLi) vulnerability discovered in WordPress WooCommerce plugin (versions <= 5.5.0).

Affected:
up to 5.5.1
Fixed in:
5.5.1
Disclosed:
Jul 15, 2021

WooCommerce < 5.5 - Authenticated Blind SQL Injection

high

Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 5.5. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `/wp-json/wc/v3...

CVSS:
8.8
Affected:
up to 3.3, 3.3 – 3.3.5, 3.4 – 3.4.7, 3.5 – 3.5.8, 3.6 – 3.6.5, 3.7 – 3.7.1, 3.8 – 3.8.1, 3.9 – 3.9.3, 4.0 – 4.0.1, 4.1 – 4.1.1, 4.2 – 4.2.2, 4.3 – 4.3.3, 4.4 – 4.4.1, 4.5 – 4.5.2, 4.6 – 4.6.2, 4.7 – 4.7.1, 4.8 – 4.8, 4.9 – 4.9.2, 5.0 – 5.0, 5.1 – 5.1, 5.2 – 5.2.2, 5.3 – 5.3, 5.4 – 5.4.1, 5.5 – 5.5
Fixed in:
3.3.6
Disclosed:
Jul 13, 2021

CVE-2021-32790 on NVD →

WooCommerce [woocommerce] < 5.2.0

unknown

[en] When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

Affected:
up to 5.2.0
Fixed in:
5.2.0
Disclosed:
May 17, 2021

CVE-2021-24323 on NVD →

WooCommerce [woocommerce] < 5.2.0

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress WooCommerce plugin (versions <= 5.1.0).

Affected:
up to 5.2.0
Fixed in:
5.2.0
Disclosed:
Apr 29, 2021

WooCommerce <= 5.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Additional tax classes' field when the tax functionality of WooCommerce is enabled in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

CVSS:
4.8
Affected:
up to 5.2.0
Fixed in:
5.2.0
Disclosed:
Apr 21, 2021

CVE-2021-24323 on NVD →

WooCommerce [woocommerce] < 4.7.0

unknown

[en] The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

Affected:
up to 4.7.0
Fixed in:
4.7.0
Disclosed:
Dec 27, 2020

CVE-2020-29156 on NVD →

WooCommerce [woocommerce] < 4.6.2

unknown

Guest Account Creation vulnerability found in WordPress WooCommerce plugin (versions <= 4.6.1).

Affected:
up to 4.6.2
Fixed in:
4.6.2
Disclosed:
Nov 6, 2020

WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation

medium

The WooCommerce plugin for WordPress is vulnerable to unauthorized user account creation during checkout even when the “Allow customers to create an account during checkout” setting is disabled. was disabled due to missing authorization checks in versions up to and including 4.6.1. The WooCommerce Blocks plugin for Wor...

CVSS:
6.5
Affected:
up to 4.6.2
Fixed in:
4.6.2
Disclosed:
Nov 5, 2020

WooCommerce [woocommerce] < 4.6.2

unknown

The WooCommerce plugin for WordPress is vulnerable to unauthorized user account creation during checkout even when the “Allow customers to create an account during checkout” setting is disabled. was disabled due to missing authorization checks in versions up to and including 4.6.1. The WooCommerce Blocks plugin for Wor...

Affected:
up to 4.6.2
Fixed in:
4.6.2
Disclosed:
Nov 5, 2020

WooCommerce <= 4.2.0 - Reflected Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing sanitization and escaping in SelectWoo, that makes it possible for attackers to inject arbitrary web scripts. This affects versions up to 4.2.1.

CVSS:
6.1
Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Jun 22, 2020

WooCommerce [woocommerce] < 4.2.1

unknown

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing sanitization and escaping in SelectWoo, that makes it possible for attackers to inject arbitrary web scripts. This affects versions up to 4.2.1.

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Jun 22, 2020

WooCommerce <= 4.0.4 - Unauthorized Post Meta Creation/Modification

high

The WooCommerce plugin for WordPress is vulnerable to arbitrary product meta data creation/overwriting due to a lack of escaping and validation on the post meta data being supplied during product duplication in versions up to, and including 4.0.4. This makes it possible for authenticated attackers, with product dupli...

CVSS:
8.8
Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
May 5, 2020

WooCommerce [woocommerce] < 4.1.0

unknown

The WooCommerce plugin for WordPress is vulnerable to arbitrary product meta data creation/overwriting due to a lack of escaping and validation on the post meta data being supplied during product duplication in versions up to, and including 4.0.4. This makes it possible for authenticated attackers, with product dupli...

Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
May 5, 2020

WooCommerce < 4.7.0 - Insecure Direct Object Reference via order_id Parameter

medium

The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

CVSS:
5.3
Affected:
up to 4.7.0
Fixed in:
4.7.0
Disclosed:
Jan 21, 2020

CVE-2020-29156 on NVD →

WooCommerce [woocommerce] < 3.6.5

unknown

Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WooCommerce plugin (versions <= 3.6.4).

Affected:
up to 3.6.5
Fixed in:
3.6.5
Disclosed:
Jul 7, 2019

WooCommerce <= 3.6.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 3.6.4, due to the CSV importer actions missing a nonce validation. This makes it possible for attackers with at least author privileges to embed script code in a CSV, upload it to the target site, and then...

CVSS:
8.8
Affected:
up to 3.6.5
Fixed in:
3.6.5
Disclosed:
Jul 2, 2019

WooCommerce <= 3.6.4 - Missing File Type Validation

high

The WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads via the tax rate importer due to missing file type validation that made it possible for high level authenticated attackers to upload malicious files in versions up to, and including, 3.6.4.

CVSS:
7.2
Affected:
up to 3.6.4
Fixed in:
3.6.5
Disclosed:
Jul 2, 2019

WooCommerce [woocommerce] < 3.6.5

unknown

The WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads via the tax rate importer due to missing file type validation that made it possible for high level authenticated attackers to upload malicious files in versions up to, and including, 3.6.4.

Affected:
up to 3.6.5
Fixed in:
3.6.5
Disclosed:
Jul 2, 2019

WooCommerce [woocommerce] < 3.6.5

unknown

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 3.6.4, due to the CSV importer actions missing a nonce validation. This makes it possible for attackers with at least author privileges to embed script code in a CSV, upload it to the target site, and then...

Affected:
up to 3.6.5
Fixed in:
3.6.5
Disclosed:
Jul 2, 2019

WooCommerce [woocommerce] < 3.5.5

unknown

[en] WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.

Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Feb 26, 2019

CVE-2019-9168 on NVD →

WooCommerce <= 3.5.4 - Stored Cross-Site Scripting

medium

WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.

CVSS:
6.1
Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Feb 20, 2019

CVE-2019-9168 on NVD →

WooCommerce [woocommerce] < 3.2.4

unknown

[en] In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/...

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Jan 15, 2019

CVE-2017-18356 on NVD →

WooCommerce [woocommerce] < 3.4.6

unknown

[en] The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.

Affected:
up to 3.4.6
Fixed in:
3.4.6
Disclosed:
Jan 15, 2019

CVE-2018-20714 on NVD →

WooCommerce [woocommerce] < 3.5.1

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Ripstech in WordPress WooCommerce plugin (versions <= 3.5.0).

Affected:
up to 3.5.1
Fixed in:
3.5.1
Disclosed:
Jan 7, 2019

WooCommerce [woocommerce] < 3.4.6

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found in WordPress WooCommerce plugin (versions <= 3.4.5).

Affected:
up to 3.4.6
Fixed in:
3.4.6
Disclosed:
Dec 11, 2018

WooCommerce <= 3.5.1 - Authenticated Stored Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting due to sanitization and escaping on an unspecific variable, that makes it possible for attackers to inject arbitrary web scripts into pages. This affects versions up to 3.5.0, and can be exploited by users with write-access API keys.

CVSS:
5.5
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Nov 29, 2018

WooCommerce [woocommerce] < 3.5.2

unknown

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting due to sanitization and escaping on an unspecific variable, that makes it possible for attackers to inject arbitrary web scripts into pages. This affects versions up to 3.5.0, and can be exploited by users with write-access API keys.

Affected:
up to 3.5.2
Fixed in:
3.5.2
Disclosed:
Nov 29, 2018

WooCommerce [woocommerce] < 3.4.6

unknown

Authenticated File Deletion to Privilege Escalation vulnerability found in WordPress WooCommerce plugin (versions <= 3.4.5).

Affected:
up to 3.4.6
Fixed in:
3.4.6
Disclosed:
Nov 7, 2018

WooCommerce <= 3.4.5 - WooCommerce File Deletion

high

The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.

CVSS:
7.2
Affected:
up to 3.4.6
Fixed in:
3.4.6
Disclosed:
Nov 6, 2018

CVE-2018-20714 on NVD →

WooCommerce [woocommerce] < 3.4.6

unknown

Authenticated Object Injection vulnerability found by Slavco in WordPress WooCommerce plugin (versions <= 3.4.5).

Affected:
up to 3.4.6
Fixed in:
3.4.6
Disclosed:
Oct 29, 2018

WooCommerce [woocommerce] < 3.4.5

unknown

According to WooCommerce, versions, 3.4.4 and earlier are affected by an issue where a function that updates attributes could lead to object injection, related to the WordPress 4.8.3 security release.

Affected:
up to 3.4.5
Fixed in:
3.4.5
Disclosed:
Sep 1, 2018

WooCommerce <= 3.4.4 - Authenticated PHP Object Injection

medium

The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection by users with access to edit attributes in versions up to, and including 3.4.4.

CVSS:
6.6
Affected:
up to 3.4.5
Fixed in:
3.4.5
Disclosed:
Aug 29, 2018

WooCommerce [woocommerce] < 3.4.5

unknown

The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection by users with access to edit attributes in versions up to, and including 3.4.4.

Affected:
up to 3.4.5
Fixed in:
3.4.5
Disclosed:
Aug 29, 2018

WooCommerce [woocommerce] < 3.2.4

unknown

Authenticated PHP Object Injection vulnerability found in WordPress WooCommerce plugin (versions <=3.2.3).

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Feb 23, 2018

WooCommerce [woocommerce] >= 2.3 - <= 2.3.5

unknown

[en] Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

Affected:
2.3 – 2.3.5
Fixed in:
2.3.5
Disclosed:
Feb 8, 2018

CVE-2015-2329 on NVD →

WooCommerce [woocommerce] < 4.0

unknown

[en] The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traversal is not possible because all of the template files have "if (!...

Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Nov 29, 2017

CVE-2017-17058 on NVD →

WooCommerce <= 3.2.3 - Authenticated PHP Object Injection

high

In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/short...

CVSS:
8.8
Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Nov 16, 2017

CVE-2017-18356 on NVD →

WooCommerce [woocommerce] < 2.6.9

unknown

[en] Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Jan 4, 2017

CVE-2016-10112 on NVD →

WooCommerce <= 2.6.8 - Authenticated Stored Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.

CVSS:
5.5
Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Dec 7, 2016

CVE-2016-10112 on NVD →

WooCommerce [woocommerce] < 2.6.4

unknown

This plugin is prone to stored cross site scripting vulnerability via REST API. Update the plugin.

Affected:
up to 2.6.4
Fixed in:
2.6.4
Disclosed:
Sep 9, 2016

WooCommerce <= 2.6.3 - Stored Cross-Site Scripting via REST-API

medium

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image uploader feature powered by the /wc-api/v3/products/categories/ REST-API in versions up to, and including, 2.6.3 due to insufficient filetype validation. This makes it possible for authenticated attackers to inject arbitrary...

CVSS:
6.4
Affected:
up to 2.6.4
Fixed in:
2.6.4
Disclosed:
Jul 26, 2016

WooCommerce [woocommerce] < 2.6.4

unknown

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image uploader feature powered by the /wc-api/v3/products/categories/ REST-API in versions up to, and including, 2.6.3 due to insufficient filetype validation. This makes it possible for authenticated attackers to inject arbitrary...

Affected:
up to 2.6.4
Fixed in:
2.6.4
Disclosed:
Jul 26, 2016

WooCommerce [woocommerce] < 2.6.3

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Jul 20, 2016

WooCommerce <= 2.6.2 - Stored Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image EXIF metadata in versions up to, and including, 2.6.2 due to insufficient validation on image files EXIF content. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute when...

CVSS:
6.4
Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Jul 19, 2016

WooCommerce [woocommerce] < 2.6.3

unknown

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image EXIF metadata in versions up to, and including, 2.6.2 due to insufficient validation on image files EXIF content. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute when...

Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Jul 19, 2016

WooCommerce < 2.4.9 - Cross-site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the pay_price() function, in versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in...

CVSS:
5.5
Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Nov 17, 2015

WooCommerce [woocommerce] < 2.4.9

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Nov 17, 2015

WooCommerce [woocommerce] < 2.4.9

unknown

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the pay_price() function, in versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in...

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Nov 17, 2015

WooCommerce [woocommerce] < 2.3.11

unknown

This plugin has a PHP bug which allows to download critical files. Attacker can access to these files and compromise site. Update the plugin.

Affected:
up to 2.3.11
Fixed in:
2.3.11
Disclosed:
Jun 17, 2015

WooCommerce <= 2.3.10 - PHP Object Injection

high

The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.10 via deserialization of untrusted input from the $custom parameter. This allows authenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to exploit XXE and re...

CVSS:
7.5
Affected:
up to 2.3.10
Fixed in:
2.3.11
Disclosed:
Jun 10, 2015

WooCommerce [woocommerce] < 2.2.3

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Jun 10, 2015

WooCommerce [woocommerce] >= 2.0.20 - <= 2.3.10

unknown

The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.10 via deserialization of untrusted input from the $custom parameter. This allows authenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to exploit XXE and re...

Affected:
2.0.20 – 2.3.10
Fixed in:
2.3.10
Disclosed:
Jun 10, 2015

WooCommerce [woocommerce] < 2.0.18

unknown

his plugin is prone to a cross site scripting vulnerability via hide-wc-extensions-message parameter. Update the plugin.

Affected:
up to 2.0.18
Fixed in:
2.0.18
Disclosed:
May 15, 2015

WooCommerce [woocommerce] < 2.0.13

unknown

This plugin is prone to a cross site scripting vulnerability via index.php calc_shipping_state parameter. Update the plugin.

Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
May 15, 2015

WooCommerce [woocommerce] < 2.3.6

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
May 15, 2015

WooCommerce <= 2.3.5 - Stored Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

CVSS:
7.2
Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Mar 13, 2015

CVE-2015-2329 on NVD →

WooCommerce [woocommerce] < 2.2.11

unknown

[en] Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php.

Affected:
up to 2.2.11
Fixed in:
2.2.11
Disclosed:
Feb 24, 2015

CVE-2015-2069 on NVD →

WooCommerce <= 2.2.10 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php.

CVSS:
6.1
Affected:
up to 2.2.11
Fixed in:
2.2.11
Disclosed:
Jan 29, 2015

CVE-2015-2069 on NVD →

WooCommerce [woocommerce] < 2.2.3

unknown

[en] Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin/admin.php.

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Oct 14, 2014

CVE-2014-6313 on NVD →

WooCommerce <= 2.2.2 - Reflected Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...

CVSS:
6.1
Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Sep 17, 2014

WooCommerce [woocommerce] < 2.2.3

unknown

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Sep 17, 2014

WooCommerce <= 2.2.2 - Cross-Site Scripting via range Parameter

high

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin/admin.php.

CVSS:
7.3
Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Sep 15, 2014

CVE-2014-6313 on NVD →

WooCommerce <= 2.0.17 - Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.17 via the 'hide-wc-extensions-message' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's b...

CVSS:
6.1
Affected:
up to 2.0.17
Fixed in:
2.0.18
Disclosed:
Oct 17, 2013

WooCommerce [woocommerce] < 2.0.18

unknown

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.17 via the 'hide-wc-extensions-message' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's b...

Affected:
up to 2.0.18
Fixed in:
2.0.18
Disclosed:
Oct 17, 2013

WooCommerce <= 2.0.12 - Self-Reflected Cross-Site Scripting

medium

The WooCommerce plugin for WordPress is vulnerable to Self-Reflected Cross-Site Scripting in versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injec...

CVSS:
6.1
Affected:
up to 2.0.12
Fixed in:
2.0.13
Disclosed:
Jul 18, 2013

WooCommerce [woocommerce] < 2.0.13

unknown

The WooCommerce plugin for WordPress is vulnerable to Self-Reflected Cross-Site Scripting in versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injec...

Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
Jul 18, 2013

WooCommerce [woocommerce] < 2.2.3

unknown

The WooCommerce WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.2.3
Fixed in:
2.2.3

WooCommerce [woocommerce] < 2.0.13

unknown

The WooCommerce WordPress plugin was affected by an index.php calc_shipping_state Parameter XSS security vulnerability.

Affected:
up to 2.0.13
Fixed in:
2.0.13

WooCommerce [woocommerce] < 2.0.17

unknown

The WooCommerce WordPress plugin was affected by a hide-wc-extensions-message Parameter Reflected XSS security vulnerability.

Affected:
up to 2.0.17
Fixed in:
2.0.17

WooCommerce [woocommerce] < 6.2.1

unknown

The PayPal Standard payment gateway (deprecated since July 2021) of the plugin could allow attackers to mark an order as paid without actually making a payment, when PDT is enabled.

Affected:
up to 6.2.1
Fixed in:
6.2.1

WooCommerce [woocommerce] < 5.7.0

unknown

The plugin does not properly check for path traversal when importing tax rates. There are limited details at this stage and this advisory will be updated later on

Affected:
up to 5.7.0
Fixed in:
5.7.0

WooCommerce [woocommerce] < 5.7.0

unknown

The plugin was vulnerable to Analytics Report Leaks on some hosting configurations. As well as updating WooCommerce to at least version 5.7.0, and WooCommerce Admin to at least version 2.6.4, it is also recommended that directory listing is disabled on your host. Automattic updates were rolled out to force the vu...

Affected:
up to 5.7.0
Fixed in:
5.7.0

WooCommerce [woocommerce] < 4.6.2

unknown

Versions of WooCommerce prior to 4.6.2 contain a vulnerability that allows guest users to create accounts during checkout even when the &quot;Allow customers to create an account during checkout&quot; setting is disabled. This vulnerability is being exploited by a bot to place spam orders and create user accounts that...

Affected:
up to 4.6.2
Fixed in:
4.6.2

WooCommerce [woocommerce] < 4.2.1

unknown

A DOM based Cross-Site Scripting (XSS) vulnerability was found to affect the SelectWoo dependency that WooCommerce used. SelectWoo replaces the standard &lt;select&gt; box in web browsers.

Affected:
up to 4.2.1
Fixed in:
4.2.1

WooCommerce [woocommerce] < 4.1.0

unknown

The WooCommerce changelog file was updated with the following message: &quot;Security &ndash; Fixed unescaped meta data while duplicating products. Reported by Slavco.&quot; We will update this issue with further information as it becomes available.

Affected:
up to 4.1.0
Fixed in:
4.1.0

WooCommerce [woocommerce] < 3.6.5

unknown

Changelog mentions: Security &ndash; Introduce file type check for tax rate importer. Security &ndash; Added nonce check to CSV importer actions. RIPS Tech later released an advisory detailing the vulnerability, which can be found in the references.

Affected:
up to 3.6.5
Fixed in:
3.6.5

WooCommerce [woocommerce] < 3.5.1

unknown

The WooCommerce WordPress plugin was affected by an Authenticated Stored XSS security vulnerability.

Affected:
up to 3.5.1
Fixed in:
3.5.1

WooCommerce [woocommerce] < 3.4.6

unknown

The WooCommerce WordPress plugin was affected by an Authenticated Phar Deserialization security vulnerability.

Affected:
up to 3.4.6
Fixed in:
3.4.6

WooCommerce [woocommerce] < 3.4.6

unknown

The WooCommerce WordPress plugin was affected by an Authenticated Stored XSS security vulnerability.

Affected:
up to 3.4.6
Fixed in:
3.4.6

WooCommerce [woocommerce] < 3.4.6

unknown

According to WooCommerce: &quot;Versions 3.4.5 and earlier are affected by a handful of issues that allow Shop Managers to exceed their capabilities and perform malicious actions. These issues can be exploited by users with Shop Manager capabilities or greater, and we recommend all users running WooCommerce 3.x upgr...

Affected:
up to 3.4.6
Fixed in:
3.4.6

WooCommerce [woocommerce] < 3.4.5

unknown

According to WooCommerce: &quot;Versions 3.4.4 and earlier are affected by an issue where a function that updates attributes could lead to object injection. This is related to the WordPress 4.8.3 security release. This issue can only be exploited by users who can edit attributes and should not be possible to expl...

Affected:
up to 3.4.5
Fixed in:
3.4.5

WooCommerce [woocommerce] < 2.6.4

unknown

The WooCommerce WordPress plugin was affected by a Stored Cross Site Scripting (XSS) via REST API security vulnerability.

Affected:
up to 2.6.4
Fixed in:
2.6.4

WooCommerce [woocommerce] < 2.4.9

unknown

The WooCommerce WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.4.9
Fixed in:
2.4.9

WooCommerce [woocommerce] < 2.3.11

unknown

According to the researcher: The vulnerability is only present when WooCommerce&rsquo;s &quot;PayPal Identity Token&quot; option is set.

Affected:
up to 2.3.11
Fixed in:
2.3.11

WooCommerce [woocommerce] < 2.6.3

unknown

The WooCommerce WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.6.3
Fixed in:
2.6.3

WooCommerce [woocommerce] < 7.0.1

unknown

The plugin returns all user metadata via an AJAX action, which could allow users with a role as low as Shop Manager to access an arbitrary user&#039;s metadata which could include tokens and other potentially sensitive data

Affected:
up to 7.0.1
Fixed in:
7.0.1

WooCommerce [woocommerce] < 7.9

unknown

The plugin does not properly apply CORS on some of its API endpoints, allowing attackers to leak customers PII information.

Affected:
up to 7.9
Fixed in:
7.9

WooCommerce [woocommerce] < 7.0.1

unknown

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.0. This can allow authenticated attackers with Shop Manager privileges or above to extract sensitive user metadata including session tokens.

Affected:
up to 7.0.1
Fixed in:
7.0.1

WooCommerce [woocommerce] < 7.9.0

unknown

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API&#039;s REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user informati...

Affected:
up to 7.9.0
Fixed in:
7.9.0

WooCommerce [woocommerce] < 8.4.0

unknown

Update the WordPress WooCommerce plugin to the latest available version (at least 8.4.0). An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WooCommerce Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other...

Affected:
up to 8.4.0
Fixed in:
8.4.0

WooCommerce [woocommerce] < 8.4.0

unknown

The plugin does not properly sanitize user-input provided by the add_query_arg() function when echoed back into JavaScript code context.

Affected:
up to 8.4.0
Fixed in:
8.4.0

WooCommerce [woocommerce] <= 9.4.2 (unfixed)

unknown
Affected:
up to 9.4.2
Fix:
No patched version reported

CVE-2025-5062 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database