Exposure of WooCommerce

Ecommerce, WordPress plugins
2,628
exposure score
568,489
sites use
0
exploited
186
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,368 results
CVE-2024-37932HIGHWordPress Woocommerce OpenPos plugin <= 6.4.4 - Unauthenticated Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-7547MEDIUMWoosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' ParameterEPSS 0.6%CVE-2023-40010CRITICALWordPress HUSKY – Products Filter for WooCommerce (formerly WOOF) Plugin <= 1.3.4.2 is vulnerable to SQL InjectionEPSS 0.6%CVE-2022-1469FiboSearch < 1.18.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-49817HIGHWordPress Flexible Woocommerce Checkout Field Editor plugin <= 2.0.1 - Broken Access Control vulnerabilityEPSS 0.6%CVE-2025-30791HIGHWordPress Cart tracking for WooCommerce plugin <= 1.0.16 - SQL Injection VulnerabilityEPSS 0.6%CVE-2023-5703MEDIUMGift Up Gift Cards for WordPress and WooCommerce <= 2.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.6%CVE-2024-34812MEDIUMWordPress ShopBuilder plugin <= 2.1.8 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-13831HIGHTabs for WooCommerce <= 1.0.0 - Authentiated (Shop Manager+) PHP Object Injection in product_has_custom_tabsEPSS 0.6%CVE-2021-4353MEDIUMWooCommerce Dynamic Pricing and Discounts <= 2.4.1 - Unauthenticated Settings Import/ExportEPSS 0.6%CVE-2023-4423MEDIUMWP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.37.1 - Authenticated (Admin+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2022-2575WBW Currency Switcher for WooCommerce < 1.6.6 - Admin+ Stored XSSEPSS 0.6%CVE-2026-10628MEDIUMPoints and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX ActionsEPSS 0.6%CVE-2024-21747HIGHWordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL InjectionEPSS 0.6%CVE-2022-3995MEDIUMTeraWallet – For WooCommerce <= 1.4.3 - Insecure Direct Object ReferenceEPSS 0.6%CVE-2025-6222CRITICALWooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet <= 3.2.6 - Unauthenticated Arbitrary File UploadEPSS 0.6%CVE-2024-9289CRITICALWordPress & WooCommerce Affiliate Program <= 8.4.1 - Authentication Bypass to Account Takeover and Privilege EscalationEPSS 0.6%CVE-2024-22147HIGHWordPress WooCommerce PDF Invoices & Packing Slips Plugin <= 3.7.5 is vulnerable to SQL InjectionEPSS 0.6%CVE-2021-4372MEDIUMWooCommerce Dynamic Pricing and Discounts <= 2.4.1 - Stored Cross-Site ScriptingEPSS 0.6%CVE-2024-10959HIGHActive Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.5 - Unauthenticated Arbitrary Shortcode Execution via woot_get_smthEPSS 0.6%