Exposure of WooCommerce

Ecommerce, WordPress plugins
2,628
exposure score
568,489
sites use
0
exploited
186
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,368 results
CVE-2025-24373MEDIUMUnrestricted Access to PDF Documents via URL Manipulation in woocommerce-pdf-invoices-packing-slipsEPSS 0.4%CVE-2024-3197MEDIUMThe Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom AttributesEPSS 0.4%CVE-2024-11362MEDIUMPayments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net <= 1.112.0 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2025-0864MEDIUMActive Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.6 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2023-32747MEDIUMWordPress WooCommerce Bookings Plugin <= 1.15.78 is vulnerable to Insecure Direct Object References (IDOR)EPSS 0.4%CVE-2025-32544HIGHWordPress WooCommerce Loyal Customers plugin <= 2.6 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-10679HIGHReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code ExecutionEPSS 0.4%CVE-2025-13077HIGHافزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce <= 1.3.5 - Unauthenticated Time-Based Blind SQL InjectionEPSS 0.4%CVE-2024-38747HIGHWordPress HitPay Payment Gateway for WooCommerce plugin <= 4.1.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2026-39472HIGHWordPress WooCommerce PDF Invoices & Packing Slips plugin < 5.9.0 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-39499HIGHWordPress Advanced Product Fields (Product Addons) for WooCommerce plugin <= 1.6.19 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2024-13525MEDIUMCustomer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2024-30469MEDIUMWordPress Wholesale For WooCommerce plugin <= 2.3.0 - Unauthenticated Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-31397CRITICALWordPress Bus Ticket Booking with Seat Reservation for WooCommerce plugin <= 1.7 - SQL Injection vulnerabilityEPSS 0.4%CVE-2025-2186HIGHRecover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.1 - Unauthenticated SQL Injection via 'automationId'EPSS 0.4%CVE-2024-53817HIGHWordPress Acowebs Product Labels For Woocommerce plugin <= 1.5.8 - SQL Injection vulnerabilityEPSS 0.4%CVE-2026-19728HIGHExtra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Disclosure via getpublicfileuploadEPSS 0.4%CVE-2022-41685MEDIUMMultiple Cross-Site Request Forgery (CSRF) vulnerabilities in Integration for Szamlazz.hu & WooCommerce and Csomagpontok és szállítási címkék WooCommerce hez pluginsEPSS 0.4%CVE-2026-49779MEDIUMWordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerabilityEPSS 0.4%CVE-2024-11815MEDIUMPósturinn\'s Shipping with WooCommerce <= 1.3.1 - Reflected Cross-Site ScriptingEPSS 0.4%