WooCommerce

Information

Software Type Plugin
Software Slug woocommerce (view on wordpress.org)
Software Status Active
Software Author woothemes
Software Website woocommerce.com
Software Downloads 304,920,558
Software Active Installs 5,000,000
Software Record Last Updated May 3, 2024

Showing 1-20 of 35 Vulnerabilities

6.1
CVE ID Unknown
Jan 12, 2024
Researchers:
5.3
CVE ID Unknown
Sep 11, 2023
Researcher: osama-hamad
4.3
CVE ID Unknown
Mar 10, 2022
Researchers:
7.2
CVE ID Unknown
Feb 22, 2022
Researchers:
6.1
CVE ID Unknown
Jun 22, 2020
Researchers:
7.2
CVE ID Unknown
Jul 2, 2019
Researchers:
Title CVE ID CVSS Researchers Date
WooCommerce <= 8.5.2 - Cross-Site Request Forgery CVE-2024-22155 4.3 Dhabaleshwar Das April 5, 2024
WooCommerce < 8.4.0 - Reflected Cross-Site Scripting 6.1 January 12, 2024
WooCommerce <= 8.2.2 - Cross-Site Request Forgery CVE-2023-52222 4.3 Rafie Muhammad January 5, 2024
WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image alt Attribute CVE-2023-47777 6.4 Rafie Muhammad November 15, 2023
WooCommerce <= 7.8.2 - Sensitive Information Exposure 5.3 osama-hamad September 11, 2023
WooCommerce <= 7.0.0 - Authenticated(Shop Manager+) Sensitive Information Exposure 4.9 David Anderson September 11, 2023
WooCommerce <= 6.5.1 - Authenticated (Admin+) HTML Injection CVE-2022-2099 5.5 Taurus Omar June 20, 2022
WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Information Disclosure 6.5 April 10, 2022
WooCommerce < 6.3.1 - Unauthorized Order Status Change 4.3 March 10, 2022
WooCommerce <= 6.2.0 - Incorrect Authorization Checks on REST API Endpoints CVE-2022-0775 5.4 Krzysztof Zając February 22, 2022
WooCommerce <= 6.2.0 - Path Traversal via Tax Importer 7.2 February 22, 2022
WooCommerce < 5.5 - Authenticated Blind SQL Injection CVE-2021-32790 8.8 Josh (jl-dos) July 13, 2021
WooCommerce <= 5.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting CVE-2021-24323 4.8 Vladislav Pokrovsky (ΞX.MI) April 21, 2021
WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation 6.5 November 5, 2020
WooCommerce <= 4.2.0 - Reflected Cross-Site Scripting 6.1 June 22, 2020
WooCommerce <= 4.0.4 - Unauthorized Post Meta Creation/Modification 8.8 Slavco Mihajloski May 5, 2020
WooCommerce < 4.7.0 - Insecure Direct Object Reference via order_id Parameter CVE-2020-29156 5.3 Ko-kn3t January 21, 2020
WooCommerce <= 3.6.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting 8.8 DENNIS BRINKROLF July 2, 2019
WooCommerce <= 3.6.4 - Missing File Type Validation 7.2 July 2, 2019
WooCommerce <= 3.5.4 - Stored Cross-Site Scripting CVE-2019-9168 6.1 Zhouyuan Yang February 20, 2019

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation