Exposure of WooCommerce

Ecommerce, WordPress plugins
2,628
exposure score
568,489
sites use
0
exploited
186
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,368 results
CVE-2024-6500CRITICALInPost for WooCommerce <= 1.4.0 and InPost PL <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary File Read and DeleteEPSS 1.0%CVE-2025-32587HIGHWordPress WooCommerce Pickupp plugin <= 2.4.3 - Local File Inclusion vulnerabilityEPSS 1.0%CVE-2024-11465HIGHCustom Product Tabs for WooCommerce <= 1.8.5 - Authenticated (Shop Manager+) PHP Object InjectionEPSS 1.0%CVE-2024-1773HIGHPDF Invoices and Packing Slips For WooCommerce <= 1.3.7 - Authenticated (Subscriber+) PHP Object InjectionEPSS 1.0%CVE-2023-2256Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site ScriptingEPSS 1.0%CVE-2022-4547HIGHConditional Payment Methods for WooCommerce <= 1.0 - Admin+ SQLiEPSS 0.9%CVE-2024-10486MEDIUMGoogle for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info FileEPSS 0.9%CVE-2026-14323HIGHPrintcart Web to Print Product Designer for WooCommerce <= 2.8.5 - Unauthenticated Arbitrary File Read via 'folder' and 'mockups' ParametersEPSS 0.9%CVE-2021-38341MEDIUMWooCommerce Payment Gateway Per Category <= 2.0.10 Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-34664MEDIUMMoova for WooCommerce <= 3.5 Reflected Cross-Site ScriptingEPSS 0.9%CVE-2024-10626HIGHWooCommerce Support Ticket System <= 17.7 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.9%CVE-2022-30998CRITICALWordPress Homepage Product Organizer for WooCommerce plugin <= 1.1 - Multiple Authenticated SQL Injection (SQLi) vulnerabilitiesEPSS 0.9%CVE-2024-13359HIGHProduct Input Fields for WooCommerce <= 1.12.0 - Unauthenticated Limited File UploadEPSS 0.9%CVE-2024-2381HIGHAliExpress Dropshipping with AliNext Lite <= 3.3.5 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2022-40194MEDIUMWordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Sensitive Information Disclosure vulnerabilityEPSS 0.9%CVE-2022-3860HIGHVisual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLiEPSS 0.9%CVE-2022-3908MEDIUMHelloprint < 1.4.7 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2022-25649MEDIUMWordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Multiple Improper Access Control vulnerabilitiesEPSS 0.9%CVE-2022-4118CRITICALBitcoin / AltCoin Payment Gateway <= 1.7.1 - Unauthenticated SQLiEPSS 0.9%CVE-2024-0952HIGHWP ERP <= 1.12.9 - Authenticated (Accounting Manager+) SQL Injection via idEPSS 0.9%