plugin

Woocommerce Store Toolkit Vulnerabilities

15 known security issues reported for the Woocommerce Store Toolkit WordPress plugin. Most recent disclosed Nov 6, 2025.

3 high 2 medium

Running Woocommerce Store Toolkit on your site? Check whether your installed version is affected.

Scan your site free

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] <= 2.4.3 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach WooCommerce Store Toolkit woocommerce-store-toolkit allows PHP Local File Inclusion.This issue affects WooCommerce Store Toolkit: from n/a through <= 2.4.3.

Affected:
up to 2.4.3
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-60204 on NVD →

WooCommerce Store Toolkit <= 2.4.3 - Unauthenticated Local File Inclusion

high

The WooCommerce Store Toolkit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.3. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass a...

CVSS:
8.1
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Jul 15, 2025

CVE-2025-60204 on NVD →

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] < 2.3.4

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] <= 2.3.4 (unfixed)

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 2.3.4
Fix:
No patched version reported
Disclosed:
Mar 4, 2022

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] < 2.3.4

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress WooCommerce Store Toolkit plugin (versions < 2.3.4).

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Feb 28, 2022

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] < 2.3.4

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress WooCommerce Store Toolkit plugin (versions < 2.3.4).

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Feb 28, 2022

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] < 2.3.4

unknown

[en] The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Feb 7, 2022

CVE-2021-25077 on NVD →

Store Toolkit for WooCommerce <= 2.3.1 - Reflected Cross-Site Scripting

medium

The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Jan 10, 2022

CVE-2021-25077 on NVD →

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] < 1.5.7

unknown

[en] The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.

Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Aug 22, 2019

CVE-2016-10922 on NVD →

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] < 1.5.8

unknown

[en] The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Aug 22, 2019

CVE-2016-10923 on NVD →

Store Toolkit for WooCommerce <= 1.5.7 - Privilege Escalation

high

The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.7. This is due to improper privilege management. This makes it possible for authenticated attackers to bypass capability checks.

CVSS:
8.8
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Feb 10, 2016

CVE-2016-10923 on NVD →

Store Toolkit for WooCommerce <= 1.5.6 - Missing Authorization

high

The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to missing authorization checks on the woo_st_admin_init() function in versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to gain access to restricted administrative actions and delete several different types of...

CVSS:
8.8
Affected:
up to 1.5.6
Fixed in:
1.5.7
Disclosed:
Feb 8, 2016

CVE-2016-10922 on NVD →

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] < 1.5.6

unknown

The plugin "WooCommerce - Store Toolkit" for WordPress suffers from a privilege escalation vulnerability. An attacker can perform the attacks easily, if he has a valid user account with which he can register to the infected website. Update the plugin.

Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Feb 8, 2016

Store Toolkit – WooCommerce Extensions, Quick Enhancements &amp; Handy Tools [woocommerce-store-toolkit] < 2.3.9

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.3.9
Fixed in:
2.3.9

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database