plugin

Woocommerce Jetpack Vulnerabilities

84 known security issues reported for the Woocommerce Jetpack WordPress plugin. Most recent disclosed Jun 23, 2026.

1 critical 10 high 28 medium

Running Woocommerce Jetpack on your site? Check whether your installed version is affected.

Scan your site free

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools <= 8.0.1 - Authenticated (Customer+) Arbitrary File Upload

high

The Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 8.0.1. This makes it possible for authenticated attackers, with Custom-level access and above...

CVSS:
8.8
Affected:
up to 8.0.1
Fixed in:
8.0.2
Disclosed:
Jun 23, 2026

CVE-2026-56027 on NVD →

Booster for WooCommerce - Broken Access Control vulnerability

medium

Broken Access Control vulnerability

CVSS:
5.3
Affected:
up to 7.11.3
Fixed in:
7.11.3
Disclosed:
Mar 17, 2026

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools < 7.11.3 - Missing Authorization

medium

The Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 7.11.3 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized...

CVSS:
5.3
Affected:
up to 7.11.3
Fixed in:
7.11.3
Disclosed:
Mar 17, 2026

CVE-2026-32586 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.4.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Stored XSS.This issue affects Booster for WooCommerce: from n/a through <= 7.3.2.

Affected:
up to 7.4.0
Fixed in:
7.4.0
Disclosed:
Nov 13, 2025

CVE-2025-64380 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.5.0

unknown

[en] Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster for WooCommerce: from n/a through <= 7.4.0.

Affected:
up to 7.5.0
Fixed in:
7.5.0
Disclosed:
Nov 13, 2025

CVE-2025-64379 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.2.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Reflected XSS.This issue affects Booster for WooCommerce: from n/a through <= 7.2.5.

Affected:
up to 7.2.6
Fixed in:
7.2.6
Disclosed:
Nov 6, 2025

CVE-2025-64196 on NVD →

Booster for WooCommerce <= 7.4.0 - Missing Authorization

medium

The Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.4.0. This makes it possible for authenticated attackers, with Subscriber-level acc...

CVSS:
4.3
Affected:
up to 7.4.0
Fixed in:
7.5.0
Disclosed:
Oct 30, 2025

CVE-2025-64379 on NVD →

Booster for WooCommerce <= 7.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts i...

CVSS:
6.4
Affected:
up to 7.3.2
Fixed in:
7.4.0
Disclosed:
Oct 18, 2025

CVE-2025-64380 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.2.5

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_order' function in all versions up to, and including, 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files with double extensions on the...

Affected:
up to 7.2.5
Fixed in:
7.2.5
Disclosed:
Aug 29, 2025

CVE-2024-13342 on NVD →

Booster for WooCommerce <= 7.2.4 - Unauthenticated Double Extension Arbitrary File Upload

high

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_order' function in all versions up to, and including, 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files with double extensions on the affe...

CVSS:
8.1
Affected:
up to 7.2.4
Fixed in:
7.2.5
Disclosed:
Aug 28, 2025

CVE-2024-13342 on NVD →

Booster for WooCommerce <= 7.2.5 - Reflected Cross-Site Scripting

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...

CVSS:
6.1
Affected:
up to 7.2.5
Fixed in:
7.2.6
Disclosed:
Apr 22, 2025

CVE-2025-64196 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.2.5

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute w...

Affected:
up to 7.2.5
Fixed in:
7.2.5
Disclosed:
Apr 4, 2025

CVE-2024-13708 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.2.5

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart function in versions 4.0.1 to 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's...

Affected:
up to 7.2.5
Fixed in:
7.2.5
Disclosed:
Apr 4, 2025

CVE-2024-13744 on NVD →

Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Stored Cross-Site Scripting

high

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenev...

CVSS:
7.2
Affected:
4.0.1 – 7.2.4
Fixed in:
7.2.5
Disclosed:
Apr 3, 2025

CVE-2024-13708 on NVD →

Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Arbitrary File Upload

high

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart function in versions 4.0.1 to 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's serv...

CVSS:
8.1
Affected:
4.0.1 – 7.2.4
Fixed in:
7.2.5
Disclosed:
Apr 3, 2025

CVE-2024-13744 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.2.6

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typically sanitizes data using wp_kses, like comments, in all versions up to, and including, 7.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

Affected:
up to 7.2.6
Fixed in:
7.2.6
Disclosed:
Apr 1, 2025

CVE-2024-12278 on NVD →

Booster for WooCommerce <= 7.2.4 - Unauthenticated Stored Cross-Site Scripting

high

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typically sanitizes data using wp_kses, like comments, in all versions up to, and including, 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated at...

CVSS:
7.2
Affected:
up to 7.2.4
Fixed in:
7.2.5
Disclosed:
Mar 31, 2025

CVE-2024-12278 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.2.4

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, 7.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...

Affected:
up to 7.2.4
Fixed in:
7.2.4
Disclosed:
Nov 26, 2024

CVE-2024-9170 on NVD →

Booster for WooCommerce <= 7.2.3 - Authenticated (ShopManager+) Stored Cross-Site Scripting via wcj_product_meta Shortcode

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, 7.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...

CVSS:
5.5
Affected:
up to 7.2.3
Fixed in:
7.2.4
Disclosed:
Nov 25, 2024

CVE-2024-9170 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.2.4

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Affected:
up to 7.2.4
Fixed in:
7.2.4
Disclosed:
Nov 20, 2024

CVE-2024-9239 on NVD →

Booster for WooCommerce <= 7.2.3 - Reflected Cross-Site Scripting

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 7.2.3
Fixed in:
7.2.4
Disclosed:
Nov 19, 2024

CVE-2024-9239 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.3

unknown

[en] Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster for WooCommerce: from n/a through 7.1.2.

Affected:
up to 7.1.3
Fixed in:
7.1.3
Disclosed:
Jun 4, 2024

CVE-2023-48747 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.9

unknown

[en] The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installed and what shortcode functional...

Affected:
up to 7.1.9
Fixed in:
7.1.9
Disclosed:
May 2, 2024

CVE-2024-3957 on NVD →

Booster for WooCommerce <= 7.1.8 - Unauthenticated Arbitrary Shortcode Execution

medium

The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installed and what shortcode functionality t...

CVSS:
6.5
Affected:
up to 7.1.8
Fixed in:
7.1.9
Disclosed:
May 1, 2024

CVE-2024-3957 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster for WooCommerce allows Reflected XSS.This issue affects Booster for WooCommerce: from n/a through 7.1.7.

Affected:
up to 7.1.8
Fixed in:
7.1.8
Disclosed:
Mar 27, 2024

CVE-2024-29760 on NVD →

Booster for WooCommerce <= 7.1.7 - Reflected Cross-Site Scripting

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...

CVSS:
6.1
Affected:
up to 7.1.7
Fixed in:
7.1.8
Disclosed:
Mar 25, 2024

CVE-2024-29760 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.8

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with con...

Affected:
up to 7.1.8
Fixed in:
7.1.8
Disclosed:
Mar 7, 2024

CVE-2024-1534 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.8

unknown

[en] The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wc_add_new_product() function in all versions up to, and including, 7.1.7. This makes it possible for customer-level attackers, and above, to upload arbitrary files on the affec...

Affected:
up to 7.1.8
Fixed in:
7.1.8
Disclosed:
Mar 7, 2024

CVE-2024-1986 on NVD →

Booster for WooCommerce <= 7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortocde

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contribu...

CVSS:
6.4
Affected:
up to 7.1.7
Fixed in:
7.1.8
Disclosed:
Mar 6, 2024

CVE-2024-1534 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.7

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wcj_product_barcode' shortcode in all versions up to, and including, 7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes like 'color'. This makes it possible fo...

Affected:
up to 7.1.7
Fixed in:
7.1.7
Disclosed:
Feb 20, 2024

CVE-2024-1054 on NVD →

Booster for WooCommerce <= 7.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wcj_product_barcode' shortcode in all versions up to, and including, 7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes like 'color'. This makes it possible for aut...

CVSS:
6.4
Affected:
up to 7.1.6
Fixed in:
7.1.7
Disclosed:
Feb 12, 2024

CVE-2024-1054 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.2

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pluggabl LLC Booster for WooCommerce.This issue affects Booster for WooCommerce: from n/a through 7.1.1.

Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Nov 30, 2023

CVE-2023-48333 on NVD →

Booster for WooCommerce <= 7.1.2 - Missing Authorization to Product Creation/Modification

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcj_product_add_new() function in all versions up to, and including, 7.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to create a...

CVSS:
4.3
Affected:
up to 7.1.2
Fixed in:
7.1.3
Disclosed:
Nov 24, 2023

CVE-2023-48747 on NVD →

Booster for WooCommerce <= 7.1.1 - Missing Authorization to Authenticated (Subscriber+) Order Information Disclosure

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_atts() function in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve arbitrary order...

CVSS:
4.3
Affected:
up to 7.1.1
Fixed in:
7.1.2
Disclosed:
Nov 24, 2023

CVE-2023-48333 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.2

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pluggabl LLC Booster for WooCommerce plugin <= 7.1.1 versions.

Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Nov 22, 2023

CVE-2023-40002 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.1

unknown

[en] The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in versions up to, and including, 7.1.0 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabi...

Affected:
up to 7.1.1
Fixed in:
7.1.1
Disclosed:
Oct 20, 2023

CVE-2023-4796 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.3

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode in versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...

Affected:
up to 7.1.3
Fixed in:
7.1.3
Disclosed:
Oct 19, 2023

CVE-2023-5638 on NVD →

Booster for WooCommerce <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode in versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-leve...

CVSS:
6.4
Affected:
up to 7.1.2
Fixed in:
7.1.3
Disclosed:
Oct 18, 2023

CVE-2023-5638 on NVD →

Booster for WooCommerce <= 7.1.1 - Authenticated (Subscriber+) Information Disclosure via Shortcode

medium

The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_get_option' shortcode in versions up to, and including, 7.1.1 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabiliti...

CVSS:
4.3
Affected:
up to 7.1.1
Fixed in:
7.1.2
Disclosed:
Oct 4, 2023

CVE-2023-40002 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.2

unknown

The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_get_option' shortcode in versions up to, and including, 7.1.1 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabiliti...

Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Oct 4, 2023

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.1

unknown

[en] The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-l...

Affected:
up to 7.1.1
Fixed in:
7.1.1
Disclosed:
Sep 14, 2023

CVE-2023-4945 on NVD →

Booster for WooCommerce <= 7.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level...

CVSS:
6.4
Affected:
up to 7.1.0
Fixed in:
7.1.1
Disclosed:
Sep 13, 2023

CVE-2023-4945 on NVD →

Booster for WooCommerce <= 7.1.0 - Authenticated (Subscriber+) Information Disclosure via Shortcode

medium

The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in versions up to, and including, 7.1.0 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabilitie...

CVSS:
4.3
Affected:
up to 7.1.0
Fixed in:
7.1.1
Disclosed:
Sep 13, 2023

CVE-2023-4796 on NVD →

Booster for WooCommerce 7.0.0 - Authenticated (Shop Manager+) Missing Authorization to Arbitrary Options Update

high

The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the 'manage_options' function in versions up to, and including, 7.0.0. This makes it possible for authenticated attackers with Shop Manager privileges to update arbitrary site option...

CVSS:
7.2
Affected:
7.0.0 – 7.0.0
Fixed in:
7.1.0
Disclosed:
Aug 1, 2023

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.0

unknown

No patched version available. PluginVulnerabilities discovered and reported this Broken Access Control vulnerability in WordPress Booster for WooCommerce Plugin. This vulnerability has not been known to be fixed yet.

Affected:
up to 7.1.0
Fixed in:
7.1.0
Disclosed:
Aug 1, 2023

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.0

unknown

The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the 'manage_options' function in versions up to, and including, 7.0.0. This makes it possible for authenticated attackers with Shop Manager privileges to update arbitrary site option...

Affected:
up to 7.1.0
Fixed in:
7.1.0
Disclosed:
Aug 1, 2023

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 6.0.1

unknown

[en] The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, Booster Elite for WooCommerce WordPress plugin before 6.0.1 have either flawed CSRF checks or are missing them completely in numerous places, allowing attackers to make logged in users perform unw...

Affected:
up to 6.0.1
Fixed in:
6.0.1
Disclosed:
Jan 23, 2023

CVE-2022-4017 on NVD →

Booster (<= 6.0.0), Booster Plus (<= 6.0.0), and Booster Elite (<= 6.0.0) for WooCommerce - Cross-Site Request Forgery

medium

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.0 (Booster), 6.0.0 (Plus), and 6.0.0 (Elite). This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthentica...

CVSS:
5.4
Affected:
up to 6.0.0
Fixed in:
6.0.1
Disclosed:
Jan 2, 2023

CVE-2022-4017 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.3

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, Booster Elite for WooCommerce WordPress plugin before 6.0.0 do not escape some URLs and parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Dec 26, 2022

CVE-2022-4227 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.7

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete a...

Affected:
up to 5.6.7
Fixed in:
5.6.7
Disclosed:
Dec 12, 2022

CVE-2022-4016 on NVD →

Booster (<= 5.6.2), Booster Plus (< 6.0.0), and Booster Elite (< 6.0.0) for WooCommerce - Reflected Cross-Site Scripting

medium

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.2 (Booster), as well as versions below 6.0.0 (Plus and Elite). This is due to insufficient input sanitization and output escaping. This makes it possible fo...

CVSS:
6.1
Affected:
up to 5.6.2
Fixed in:
5.6.3
Disclosed:
Dec 5, 2022

CVE-2022-4227 on NVD →

Booster for WooCommerce <= 5.6.8 - Cross-Site Request Forgery

high

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.8. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they...

CVSS:
8.8
Affected:
up to 5.6.8
Fixed in:
6.0.0
Disclosed:
Nov 30, 2022

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 6.0.0

unknown

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.8. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they...

Affected:
up to 6.0.0
Fixed in:
6.0.0
Disclosed:
Nov 30, 2022

Booster (<= 5.6.6), Booster Plus (<= 5.6.5), and Booster Elite (<= 1.1.7) for WooCommerce - Cross-Site Request Forgery leading to Arbitrary Custom Role Creation/Deletion

medium

The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Booster), 5.6.5 (Plus), and 1.1.7 (Elite). This is due to missing or incorrect nonce validation on functions such as 'process_actions' and 'get_delete_all_cu...

CVSS:
5.4
Affected:
up to 5.6.6
Fixed in:
5.6.7
Disclosed:
Nov 21, 2022

CVE-2022-4016 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.7

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not have CSRF check in place when deleting files uploaded at the checkout, allowing attackers to make a logged in shop manager or adm...

Affected:
up to 5.6.7
Fixed in:
5.6.7
Disclosed:
Nov 21, 2022

CVE-2022-3763 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.7

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not validate files to download in some of its modules, which could allow ShopManager and Admin to download arbitrary files from the s...

Affected:
up to 5.6.7
Fixed in:
5.6.7
Disclosed:
Nov 21, 2022

CVE-2022-3762 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Booster for WooCommerce plugin <= 5.6.6 on WordPress.

Affected:
up to 5.6.7
Fixed in:
5.6.7
Disclosed:
Nov 18, 2022

CVE-2022-41805 on NVD →

Booster for WooCommerce (Free <= 5.6.6, Premium <= 5.6.4) - Cross-Site Request Forgery to File Deletion

high

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6 (Free) and 5.6.4 (Premium). This is due to missing or incorrect nonce validation when deleting files uploaded during checkout. This makes it possible for unauthenticated attackers to dele...

CVSS:
8.8
Affected:
up to 5.6.6
Fixed in:
5.6.7
Disclosed:
Oct 31, 2022

CVE-2022-3763 on NVD →

Booster for WooCommerce <= 5.6.6 - Cross-Site Request Forgery

high

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.6. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they...

CVSS:
8.8
Affected:
up to 5.6.6
Fixed in:
5.6.7
Disclosed:
Oct 27, 2022

CVE-2022-41805 on NVD →

Booster (<= 5.6.6) and Booster Plus (<= 5.6.4) for WooCommerce - Authenticated (Shop Manager+) Information Exposure via Arbitrary File Download

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file downloads due to missing sanitization and filename validation of a user-supplied parameter in versions up to, and including, 5.6.6 (5.6.4 for Booster Plus). This makes it possible for authenticated attackers, with Shop Manager-level permis...

CVSS:
6.5
Affected:
up to 5.6.6
Fixed in:
5.6.7
Disclosed:
Oct 27, 2022

CVE-2022-3762 on NVD →

Booster for WooCommerce (Free <= 5.6.2 and Premium <= 5.6.0) - Authenticated (Subscriber+) Order Modification

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to order modification due to a missing capability/authorization check in versions up to, and including, 5.6.2 (free) or 5.6.0 (premium). This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify their own ord...

CVSS:
6.5
Affected:
up to 5.6.2
Fixed in:
5.6.3
Disclosed:
Sep 19, 2022

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.3

unknown

The Booster for WooCommerce plugin for WordPress is vulnerable to order modification due to a missing capability/authorization check in versions up to, and including, 5.6.2 (free) or 5.6.0 (premium). This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify their own ord...

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Sep 19, 2022

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.3

unknown

Authenticated Order Status Update vulnerability discovered by WPScan in WordPress Booster for WooCommerce plugin (versions <= 5.6.2). Update the WordPress Booster for WooCommerce plugin to the latest available version (at least 5.6.3).

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Sep 19, 2022

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.3

unknown

Authenticated Order Status Update vulnerability discovered by WPScan in WordPress Booster Plus for WooCommerce premium plugin (versions <= 5.6.0). Update the WordPress Booster Plus for WooCommerce plugin to the latest available version (at least 5.6.1).

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Sep 19, 2022

Booster for WooCommerce <= 5.6.1 - Cross-Site Request Forgery

high

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.1. This is due to missing or incorrect nonce validation on several different functions. This makes it possible for unauthenticated attackers to perform several administrative actions like a...

CVSS:
8.8
Affected:
up to 5.6.1
Fixed in:
5.6.2
Disclosed:
Jul 27, 2022

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.2

unknown

The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.1. This is due to missing or incorrect nonce validation on several different functions. This makes it possible for unauthenticated attackers to perform several administrative actions like a...

Affected:
up to 5.6.2
Fixed in:
5.6.2
Disclosed:
Jul 27, 2022

Booster for WooCommerce <= 5.5.9 - Reflected Cross-Site Scripting

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to 5.5.9
Fixed in:
5.6.0
Disclosed:
Jul 4, 2022

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.0

unknown

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

Affected:
up to 5.6.0
Fixed in:
5.6.0
Disclosed:
Jul 4, 2022

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.0

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Booster for WooCommerce plugin (versions <= 5.5.9). Update the WordPress Booster for WooCommerce plugin to the latest available version (at least 5.6.0).

Affected:
up to 5.6.0
Fixed in:
5.6.0
Disclosed:
Jul 4, 2022

Booster for WooCommerce <= 5.5.8 - Reflected Cross-Site Scripting

medium

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 5.5.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 5.5.8
Fixed in:
5.5.9
Disclosed:
May 31, 2022

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.5.9

unknown

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 5.5.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

Affected:
up to 5.5.9
Fixed in:
5.5.9
Disclosed:
May 31, 2022

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.4.9

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_create_products_xml_result parameter before outputting back in the admin dashboard when the Product XML Feeds module is enabled, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jan 3, 2022

CVE-2021-25001 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.4.9

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_notice parameter before outputting it back in the admin dashboard when the Pdf Invoicing module is enabled, leading to a Reflected Cross-Site Scripting

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jan 3, 2022

CVE-2021-24999 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.4.9

unknown

[en] The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter before outputting back in the admin dashboard when the General module is enabled, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jan 3, 2022

CVE-2021-25000 on NVD →

Booster for WooCommerce <= 5.4.8 - Reflected Cross-Site Scripting in General Module

medium

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter before outputting back in the admin dashboard when the General module is enabled, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Dec 1, 2021

CVE-2021-25000 on NVD →

Booster for WooCommerce <= 5.4.8 - Reflected Cross-Site Scripting in PDF Invoicing Module

medium

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_notice parameter before outputting it back in the admin dashboard when the Pdf Invoicing module is enabled, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Dec 1, 2021

CVE-2021-24999 on NVD →

Booster for WooCommerce <= 5.4.8 - Reflected Cross-Site Scripting in Product XML Feeds Module

medium

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_create_products_xml_result parameter before outputting back in the admin dashboard when the Product XML Feeds module is enabled, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Dec 1, 2021

CVE-2021-25001 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.4.4

unknown

[en] Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.ph...

Affected:
up to 5.4.4
Fixed in:
5.4.4
Disclosed:
Aug 30, 2021

CVE-2021-34646 on NVD →

Booster for WooCommerce <= 5.4.3 - Authentication Bypass

critical

Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php fil...

CVSS:
9.8
Affected:
up to 5.4.3
Fixed in:
5.4.4
Disclosed:
Aug 24, 2021

CVE-2021-34646 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 3.8.0

unknown

[en] The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.

Affected:
up to 3.8.0
Fixed in:
3.8.0
Disclosed:
Aug 12, 2019

CVE-2018-20966 on NVD →

Booster for WooCommerce <= 3.7.0 - Cross-Site Scripting

medium

The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.

CVSS:
6.1
Affected:
up to 3.8.0
Fixed in:
3.8.0
Disclosed:
Jul 28, 2018

CVE-2018-20966 on NVD →

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.2

unknown

The plugin does not escape some generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 5.6.2
Fixed in:
5.6.2

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 7.1.0

unknown

The plugin is vulnerable to unauthorized modification of data due to a missing capability check on the &#039;manage_options&#039; function in versions up to, and including, 7.0.0. This makes it possible for authenticated attackers with Shop Manager privileges to update arbitrary site options.

Affected:
up to 7.1.0
Fixed in:
7.1.0

Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches &amp; 100+ Tools [woocommerce-jetpack] < 5.6.3

unknown

The plugins allow users to update their own order status via a settings defined by admins when the My Account module is enabled, however does not ensure that the status set is allowed. As a result, users could set arbitrary status to their own orders, making them paid without actually paying for them even though admins...

Affected:
up to 5.6.3
Fixed in:
5.6.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database