Exposure of WooCommerce

Ecommerce, WordPress plugins
1,859
exposure score
591,334
sites use
0
exploited
159
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,053 results
CVE-2023-7067MEDIUMShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_storeEPSS 0.3%CVE-2022-4017HIGHBooster for WooCommerce - Multiple CSRFEPSS 0.3%CVE-2024-52460HIGHWordPress AtaraPay WooCommerce Payment Gateway plugin <= 2.0.13 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2023-52232MEDIUMWordPress Booster Plus for WooCommerce plugin < 7.1.2 - Authenticated Arbitrary Post/Page Deletion VulnerabilityEPSS 0.3%CVE-2020-36834MEDIUMDiscount Rules for WooCommerce <= 2.0.2 - Missing AuthorizationEPSS 0.3%CVE-2024-32834MEDIUMWordPress WooCommerce Shipping Label plugin <= 2.3.8 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-3743MEDIUMUpsell Funnel Builder for WooCommerce <= 3.0.0 - Unauthenticated Order ManipulationEPSS 0.3%CVE-2025-22639HIGHWordPress Distance Rate Shipping for WooCommerce plugin <= 1.3.4 - SQL Injection vulnerabilityEPSS 0.3%CVE-2022-4016MEDIUMBooster for WooCommerce - Custom Role Creation/Deletion via CSRFEPSS 0.3%CVE-2024-11938MEDIUMOne Click Upsell Funnel for WooCommerce <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via wps_wocuf_pro_yes ShortcodeEPSS 0.3%CVE-2024-11324MEDIUMAccounting for WooCommerce <= 1.6.6 - Reflected Cross-Site ScriptingEPSS 0.3%CVE-2024-32585MEDIUMWordPress Import Content in WordPress & WooCommerce with Excel plugin <= 4.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2026-2232HIGHProduct Table and List Builder for WooCommerce Lite <= 4.6.2 - Unauthenticated Time-Based SQL Injection via 'search' ParameterEPSS 0.3%CVE-2023-2179MEDIUMWooCommerce Order Status Change Notifier <= 1.1.0 - Subscriber+ Arbitrary Order Status UpdateEPSS 0.3%CVE-2023-46635MEDIUMWordPress YITH WooCommerce Product Add-Ons plugin <= 4.2.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-32522MEDIUMWordPress Open Close WooCommerce Store plugin <= 4.9.1 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-32520MEDIUMWordPress WPC Grouped Product for WooCommerce plugin <= 4.4.2 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2023-51692MEDIUMWordPress Customer Reviews for WooCommerce Plugin <= 5.38.1 is vulnerable to Broken Access ControlEPSS 0.3%CVE-2024-32517MEDIUMWordPress Custom Thank You Page Customize For WooCommerce by Binary Carpenter plugin <= 1.4.12 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-32519MEDIUMWordPress GG Woo Feed for WooCommerce plugin <= 1.2.6 - Broken Access Control vulnerabilityEPSS 0.3%

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →