Exposure of WooCommerce

Ecommerce, WordPress plugins
1,859
exposure score
591,334
sites use
0
exploited
159
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,053 results
CVE-2024-9237MEDIUMFish and Ships <= 1.5.9 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-9213MEDIUMPersian WooCommerce SMS <= 7.0.2 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2026-49061HIGHWordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2024-6637HIGHWooCommerce - Social Login <= 2.7.3 - Unauthenticated Privilege Escalation via One-Time PasswordEPSS 0.4%CVE-2024-5665MEDIUMLogin/Signup Popup ( Inline Form + Woocommerce ) 2.7.1 - 2.7.2 - Missing Authorization to Arbitrary Options ExposureEPSS 0.4%CVE-2024-6579MEDIUMWeb and WooCommerce Addons for WPBakery Builder <= 1.4.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings ModificationEPSS 0.4%CVE-2023-23667MEDIUMWordPress Brands for WooCommerce Plugin <= 3.7.0.6 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2024-56009MEDIUMWordPress Spreadr Woocommerce plugin <= 1.0.4 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-24767CRITICALWordPress TicketBAI Facturas para WooCommerce plugin <= 3.19 - SQL Injection VulnerabilityEPSS 0.4%CVE-2024-8668MEDIUMShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site ScriptingEPSS 0.4%CVE-2024-8793MEDIUMStore Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More <= 2.7.2.1 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2025-14460MEDIUMPiraeus Bank WooCommerce Payment Gateway <= 3.1.4 - Missing Authorization to Unauthenticated Arbitrary Order Status ChangeEPSS 0.4%CVE-2025-47641CRITICALWordPress Printcart Web to Print Product Designer for WooCommerce plugin <= 2.3.9 - Arbitrary File Upload VulnerabilityEPSS 0.4%CVE-2026-3830HIGHProduct Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQLiEPSS 0.4%CVE-2024-22153MEDIUMWordPress Stock Locations for WooCommerce Plugin <= 2.5.9 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2023-28783MEDIUMWordPress Woocommerce Tip/Donation Plugin <= 1.2 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2023-37870HIGHWordPress WooCommerce Warranty Requests plugin <= 2.1.9 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-3345MEDIUMShopLentor <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch ShortcodeEPSS 0.4%CVE-2024-13355MEDIUMAdmin and Customer Messages After Order for WooCommerce <= 13.2 - Authenticated (Subscriber+) Limited File Upload to Cross-Site ScriptingEPSS 0.4%CVE-2023-4947MEDIUMWooCommerce EAN Payment Gateway < 6.1.0 - Missing Authorization to Authenticated (Contributor+) EAN UpdateEPSS 0.4%

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →