Product
woocommerce
42 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-5062
CVE-2024-9944
CVE-2023-35049
CVE-2023-51497
CVE-2023-51496
CVE-2023-51495
CVE-2024-37297
CVE-2023-34003
CVE-2024-1310
CVE-2023-44999
CVE-2024-24799
CVE-2022-0775
CVE-2023-52222
CVE-2023-32799
CVE-2023-33318
CVE-2023-33330
CVE-2023-32743
CVE-2023-47777
CVE-2023-32745
CVE-2023-33317
CVE-2023-32802
CVE-2023-32793
CVE-2023-32575
CVE-2023-37873
CVE-2023-3508
CVE-2023-3507
CVE-2023-36514
CVE-2023-36513
CVE-2023-34000
CVE-2023-33319
CVE-2023-33316
CVE-2022-2099
CVE-2021-32790
CVE-2021-24323
CVE-2020-29156
CVE-2019-20891
CVE-2019-9168
CVE-2018-20714
CVE-2017-18356
CVE-2015-2329
CVE-2017-17058
CVE-2016-10112
< 9.3.4
The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all
< 9.1.0
The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to t
< 7.4.1
Missing Authorization vulnerability in WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Paymen
< 3.8.10
Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple
< 2.3.0
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/
< 2.3.0
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/
>= 8.8 and < 8.8.5
WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cro
< 1.1.52
Missing Authorization vulnerability in Woo WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.1.
< 8.6
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they s
<= 7.6.0
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Stripe Payment Gateway.This issue affects WooCommerce S
< 1.2.3
Missing Authorization vulnerability in WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a thro
< 6.2.1
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow an
<= 8.2.2
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.
<= 3.8.3
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipp
<= 4.9.40
Unrestricted Upload of File with Dangerous Type vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a
< 4.9.51
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This
< 5.7.2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This
<= 8.1.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Auto
<= 5.7.1
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.1 versions.
<= 2.1.6
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Returns and Warranty Requests plugin <= 2.1.6 versions.
<= 1.9.0
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Pre-Orders plugin <= 1.9.0 versions.
<= 2.0.0
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce Pre-Orders plugin <= 2.0.0 versio
<= 1.3.25
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce
<= 3.8.5
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions.
< 2.0.3
The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allo
< 2.0.3
The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow atta
<= 3.8.5
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions.
<= 5.7.5
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions.
< 7.4.1
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.
<= 4.9.40
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.
< 4.9.50
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versio
< 6.6.0
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the
>= 3.3.0 and < 3.3.6
Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running
< 5.2.0
When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the a
< 4.7.0
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id
< 3.6.5
WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant st
< 3.5.5
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
< 3.4.6
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability.
< 3.2.4
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site wit
< 2.3.6
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject ar
<= 3.2.6
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/tem
<= 2.6.8
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administ