Exposure of WooCommerce

Ecommerce, WordPress plugins
1,859
exposure score
591,334
sites use
0
exploited
159
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,053 results
CVE-2025-60211HIGHWordPress WooCommerce Registration Fields Plugin - Custom Signup Fields plugin <= 3.2.3 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-60222HIGHWordPress SUMO Memberships for WooCommerce plugin <= 7.8.0 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2024-29112MEDIUMWordPress WooCommerce Google Feed Manager plugin <= 2.2.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2025-60083HIGHWordPress PDF Invoice Builder for WooCommerce plugin <= 6.5.0 - Deserialization of untrusted data vulnerabilityEPSS 0.4%CVE-2025-47537HIGHWordPress PDF Invoice Builder for WooCommerce plugin <= 5.3.8 - SQL Injection VulnerabilityEPSS 0.4%CVE-2025-49315HIGHWordPress Persian Woocommerce SMS plugin <= 7.0.10 - SQL Injection VulnerabilityEPSS 0.4%CVE-2025-47643HIGHWordPress ELEX Product Feed for WooCommerce <= 3.1.2 - SQL Injection VulnerabilityEPSS 0.4%CVE-2025-47460HIGHWordPress TrackShip for WooCommerce plugin <= 1.9.1 - SQL Injection VulnerabilityEPSS 0.4%CVE-2023-51495MEDIUMWordPress WooCommerce Warranty Requests plugin <= 2.2.7 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-4564MEDIUMCoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple WidgetsEPSS 0.4%CVE-2024-8800MEDIUMRabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more <= 2.21.0 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-9345MEDIUMProduct Delivery Date for WooCommerce – Lite <= 2.7.3 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-9384MEDIUMQuantity Dynamic Pricing & Bulk Discounts for WooCommerce <= 3.8.0 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-44006MEDIUMWordPress WooCommerce Multilingual & Multicurrency plugin <= 5.3.7 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-38680HIGHWordPress Appmaker plugin <= 1.36.12 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2023-46822HIGHWordPress WooCommerce – Store Exporter Plugin <= 2.7.2 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2026-25328MEDIUMWordPress Product File Upload for WooCommerce plugin <= 2.2.4 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2024-8724MEDIUMWaitlist Woocommerce ( Back in stock notifier ) <= 2.7.5 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-12435MEDIUMCompare Products for WooCommerce <= 3.2.1 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-11369MEDIUMStore credit / Gift cards for woocommerce <= 1.0.49.46 - Reflected Cross-Site ScriptingEPSS 0.4%

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →