Exposure of WooCommerce

Ecommerce, WordPress plugins
2,628
exposure score
568,489
sites use
0
exploited
186
critical
Vexday analysis

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2,368 results
CVE-2022-46856MEDIUMWordPress Woocommerce Product Designer Plugin <= 4.3.3 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2022-43488MEDIUMWordPress Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 - Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.3%CVE-2022-36401MEDIUMWordPress TeraWallet – For WooCommerce Plugin <= 1.3.24 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2022-46815MEDIUMWordPress Conditional Shipping for WooCommerce Plugin <= 2.3.1 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2025-14173MEDIUMPerfit WooCommerce <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings DeletionEPSS 0.3%CVE-2025-6215MEDIUMOmnishop <= 1.0.9 - Missing Registration Restriction to Unauthenticated Account Creation via /users/register REST EndpointEPSS 0.3%CVE-2025-12895MEDIUMKalium <= 3.29 - Missing Authorization to Unauthenticated Mail Relay via kalium_vc_contact_form_requestEPSS 0.3%CVE-2025-14880MEDIUMNetcash WooCommerce Payment Gateway <= 4.1.3 - Missing Authorization to Unauthenticated Order Status ModificationEPSS 0.3%CVE-2025-14948MEDIUMminiOrange OTP Verification and SMS Notification for WooCommerce <= 4.3.8 - Missing Authorization to Unauthenticated Notification Settings ModificationEPSS 0.3%CVE-2024-13519MEDIUMMarketKing — Ultimate WooCommerce Multivendor Marketplace Solution <= 1.9.80 - Authenticated (Shop Manager+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-12411HIGHPremmerce Wholesale Pricing for WooCommerce <= 1.1.10 - Authenticated (Subscriber+) SQL InjectionEPSS 0.3%CVE-2024-2784MEDIUMThe Plus Addons for Elementor <= 5.5.4 - Authenticated (Contibutor+) Stored Cross-Site Scripting via Hover CardEPSS 0.3%CVE-2024-5583MEDIUMThe Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget SettingsEPSS 0.3%CVE-2026-1826MEDIUMOpenPOS Lite <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesEPSS 0.3%CVE-2023-51369MEDIUMWordPress Customize My Account for WooCommerce plugin <= 1.8.3 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.3%CVE-2026-25396HIGHWordPress Commerce Coinbase For WooCommerce plugin <= 1.6.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-2800HIGHWP Event Manager <= 3.1.50 - Unauthenticated Stored Cross-Site Scripting via 'organizer_name'EPSS 0.3%CVE-2025-13157MEDIUMQODE Wishlist for WooCommerce <= 1.2.7 - Unauthenticated Insecure Direct Object Reference to Wishlist UpdateEPSS 0.3%CVE-2022-4103MEDIUMRoyal Elementor Addons < 1.3.56 - Subscriber+ Arbitrary Post CreationEPSS 0.3%CVE-2026-91008LOWEvent Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure via Booking Confirmation PanelEPSS 0.3%