plugin

Wpify Woo Vulnerabilities

10 known security issues reported for the Wpify Woo WordPress plugin. Most recent disclosed Jul 23, 2026.

2 high 3 medium

Running Wpify Woo on your site? Check whether your installed version is affected.

Scan your site free

WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint

high

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update_option() without any option-name...

CVSS:
8
Affected:
up to 5.4.16
Fixed in:
5.4.17
Disclosed:
Jul 23, 2026

CVE-2026-12736 on NVD →

WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce <= 5.4.1 - Authenticated (Contributor+) Arbitrary File Upload

high

The WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 5.4.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to...

CVSS:
8.8
Affected:
up to 5.4.1
Fixed in:
5.4.2
Disclosed:
May 29, 2026

CVE-2026-42748 on NVD →

WPify Woo Czech [wpify-woo] < 4.0.11

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPify s.R.O. WPify Woo Czech allows Reflected XSS.This issue affects WPify Woo Czech: from n/a through 4.0.10.

Affected:
up to 4.0.11
Fixed in:
4.0.11
Disclosed:
May 3, 2024

CVE-2024-33946 on NVD →

WPify Woo Czech <= 4.0.10 - Reflected Cross-Site Scripting

medium

The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...

CVSS:
6.1
Affected:
up to 4.0.10
Fixed in:
4.0.11
Disclosed:
Apr 30, 2024

CVE-2024-33946 on NVD →

WPify Woo Czech [wpify-woo] < 4.0.9

unknown

[en] The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta function in all versions up to, and including, 4.0.8. This makes it possible for unauthenticated attackers to obtain shipping details for orders as long as the order...

Affected:
up to 4.0.9
Fixed in:
4.0.9
Disclosed:
Feb 20, 2024

CVE-2024-1492 on NVD →

WPify Woo Czech <= 4.0.8 - Missing Authorization

medium

The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta function in all versions up to, and including, 4.0.8. This makes it possible for unauthenticated attackers to obtain shipping details for orders as long as the order numbe...

CVSS:
5.3
Affected:
up to 4.0.8
Fixed in:
4.0.9
Disclosed:
Feb 19, 2024

CVE-2024-1492 on NVD →

WPify Woo Czech <= 3.5.6 - Reflected Cross-Site Scripting

medium

The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of '$_SERVER['PHP_SELF']' with insufficient input sanitization and output escaping in versions up to, and including, 3.5.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
6.1
Affected:
up to 3.5.6
Fixed in:
3.5.7
Disclosed:
May 16, 2022

WPify Woo Czech [wpify-woo] < 3.5.7

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress WPify Woo Czech plugin (versions <= 3.5.6). Update the WordPress WPify Woo Czech plugin to the latest available version (at least 3.5.7).

Affected:
up to 3.5.7
Fixed in:
3.5.7
Disclosed:
May 16, 2022

WPify Woo Czech [wpify-woo] < 3.5.7

unknown

The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of '$_SERVER['PHP_SELF']' with insufficient input sanitization and output escaping in versions up to, and including, 3.5.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

Affected:
up to 3.5.7
Fixed in:
3.5.7
Disclosed:
May 16, 2022

WPify Woo Czech [wpify-woo] < 3.5.7

unknown

The plugin uses the Vies library v2.2.0, which has a sample file outputting $_SERVER[&#039;PHP_SELF&#039;] in an attribute without being escaped first, leading to a Reflected Cross-Site Scripting. The issue is only exploitable when the web server has the PDO driver installed, and write access to the example directory (...

Affected:
up to 3.5.7
Fixed in:
3.5.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database