Exposure of WooCommerce

Ecommerce, WordPress plugins
2,628
exposure score
568,489
sites use
0
exploited
186
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,368 results
CVE-2024-1310MEDIUMWooCommerce < 8.6 - Contributor+ Private/Draft Products AccessEPSS 0.7%CVE-2025-5746CRITICALDrag and Drop Multiple File Upload (Pro) - WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2024-3067HIGHWooCommerce Google Feed Manager <= 2.4.2 - Authenticated (Admin+) SQL Injection to Reflected Cross-Site ScriptingEPSS 0.7%CVE-2024-13824CRITICALCiyaShop - Multipurpose WooCommerce Theme <= 4.19.0 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2024-32781HIGHWordPress Email Customizer for WooCommerce plugin <= 2.6.0 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2024-12721HIGHCustom Product Tabs For WooCommerce <= 1.2.4 - Authenticated (Shop Manager+) PHP Object InjectionEPSS 0.7%CVE-2024-8393MEDIUMWoocommerce Blocks – Woolook <= 1.7.0 - Authenticated (Admin+) Local File InclusionEPSS 0.7%CVE-2026-15019HIGHDirect Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path SegmentEPSS 0.7%CVE-2025-4602MEDIUMeMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File ReadEPSS 0.7%CVE-2024-4371CRITICALCoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2023-41685HIGHWordPress Woocommerce Support System Plugin <= 1.2.1 is vulnerable to SQL InjectionEPSS 0.7%CVE-2026-14352HIGHAR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' ParameterEPSS 0.7%CVE-2022-0775MEDIUMWooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment DeletionEPSS 0.7%CVE-2026-15406HIGHEventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' ParameterEPSS 0.7%CVE-2024-1862HIGHWooCommerce Add to Cart Custom Redirect <= 1.2.13 - Authenticated(Contributor+) Missing Authorization to Limited Arbitrary Options UpdateEPSS 0.7%CVE-2026-4664MEDIUMCustomer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' ParameterEPSS 0.7%CVE-2026-18080CRITICALERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP AttachmentEPSS 0.7%CVE-2026-1714HIGHShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX ActionEPSS 0.7%CVE-2023-6327MEDIUMShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_productsEPSS 0.7%CVE-2021-39347MEDIUMStripe for WooCommerce 3.0.0 - 3.3.9 Missing Authorization Controls to Financial Account HijackingEPSS 0.7%