Exposure of WooCommerce

Ecommerce, WordPress plugins
1,859
exposure score
591,334
sites use
0
exploited
159
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,053 results
CVE-2024-10437MEDIUMWPC Smart Messages for WooCommerce <= 4.2.1 - Missing Authorization to Authenticated (Subscriber+) Message Activation/DeactivationEPSS 0.4%CVE-2025-22505HIGHWordPress NC Wishlist for Woocommerce Plugin <= 1.0.1 - SQL Injection vulnerabilityEPSS 0.4%CVE-2025-1912HIGHProduct Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file FunctionEPSS 0.4%CVE-2025-10862HIGHPopup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.3 - Unauthenticated SQL Injection via 'id'EPSS 0.4%CVE-2025-8416HIGHProduct Filter by WBW <= 2.9.7 - Unauthenticated SQL InjectionEPSS 0.4%CVE-2024-2322MEDIUMWooCommerce Cart Abandonment Recovery < 1.2.27 - Templates/Abandoned Orders Deletion via CSRFEPSS 0.4%CVE-2023-52230MEDIUMWordPress Booster Plus for WooCommerce plugin < 7.1.3 - Authenticated Arbitrary WordPress Option Disclosure VulnerabilityEPSS 0.4%CVE-2024-29929MEDIUMWordPress WCFM plugin <= 6.7.8 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2025-14294MEDIUMRazorpay for WooCommerce <= 4.7.8 - Missing Authentication to Unauthenticated Order ModificationEPSS 0.4%CVE-2023-50850MEDIUMWordPress Woo Subscriptions plugin < 5.8.0 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-26566HIGHWordPress In Stock Mailer for WooCommerce Plugin <= 2.1.1 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2026-45217MEDIUMWordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Authentication vulnerabilityEPSS 0.4%CVE-2025-3598MEDIUMCoupon Affiliates – Affiliate Plugin for WooCommerce <= 6.3.0 - Reflected Cross-Site Scripting via 'commission_summary' ParameterEPSS 0.4%CVE-2026-4896HIGHWCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product ManipulationEPSS 0.4%CVE-2023-51501HIGHWordPress Uncode Core Plugin <= 2.8.6 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2023-50893HIGHWordPress UpSolution Core Plugin <= 8.17.4 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2023-44144HIGHWordPress Dreamfox Media Payment gateway per Product for Woocommerce Plugin <= 3.2.7 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2023-41874HIGHWordPress Order Delivery Date for WooCommerce Plugin <= 3.20.0 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2024-35662MEDIUMWordPress Simple COD Fees for WooCommerce plugin <= 2.0.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-30466MEDIUMWordPress WooCommerce Multilingual & Multicurrency plugin <= 5.3.4 - Broken Access Control vulnerabilityEPSS 0.4%

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →