Exposure of WooCommerce

Ecommerce, WordPress plugins
2,628
exposure score
568,489
sites use
0
exploited
186
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,368 results
CVE-2021-25018PPOM for WooCommerce < 24.0 - Subscriber+ Settings Update to Stored XSSEPSS 0.5%CVE-2025-39568HIGHWordPress StoreContrl Woocommerce plugin <= 4.1.3 - Arbitrary File Download VulnerabilityEPSS 0.5%CVE-2026-6020HIGHShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST APIEPSS 0.5%CVE-2024-12812HIGHWP ERP < 1.13.4 - Custom+ Unauthorized Access to Terminated Employee InformationEPSS 0.5%CVE-2024-1960MEDIUMShopLentor <= 2.8.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Banner LinkEPSS 0.5%CVE-2024-38702MEDIUMWordPress Product Delivery Date for WooCommerce – Lite plugin <= 2.7.2 - Broken Access Control vulnerabilityEPSS 0.5%CVE-2024-23512HIGHWordPress ProductX – Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object InjectionEPSS 0.5%CVE-2024-6636CRITICALWooCommerce - Social Login <= 2.7.3 - Missing Authorization to Unauthenticated Privilege EscalationEPSS 0.5%CVE-2025-62008HIGHWordPress Product Table For WooCommerce plugin <= 1.2.4 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-47461HIGHWordPress Subaccounts for WooCommerce plugin <= 1.6.6 - Account Takeover vulnerabilityEPSS 0.5%CVE-2023-50831MEDIUMWordPress CURCY Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS)EPSS 0.5%CVE-2024-2343MEDIUMAvada <= 7.11.6 - Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_actionEPSS 0.5%CVE-2024-1119MEDIUMOrder Tip for WooCommerce <= 1.3.1 - Missing Authorization to Unauthenticated Data ExportEPSS 0.5%CVE-2023-0479MEDIUMPrint Invoice & Delivery Notes for WooCommerce < 4.7.2 - Reflected XSS EPSS 0.5%CVE-2026-76009HIGHNext-Cart Store to WooCommerce Migration <= 3.9.8 - Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration EndpointEPSS 0.5%CVE-2025-24594MEDIUMWordPress Linet ERP-Woocommerce Integration plugin <= 3.5.7 - CSRF to Broken Access Control vulnerabilityEPSS 0.5%CVE-2026-49060CRITICALWordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-1677MEDIUMPrint Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce <= 3.4.6 - Improper AuthorizationEPSS 0.5%CVE-2024-11725HIGHSMS Alert Order Notifications – WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options UpdateEPSS 0.5%CVE-2024-6353HIGHWallet for WooCommerce <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'search[value]'EPSS 0.5%