Exposición de WooCommerce

Ecommerce, WordPress plugins
2628
score de exposición
568.489
sitios usan
0
en explotación
186
críticos
Análisis Vexday

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2368 resultados
CVE-2024-1308HIGHWooCommerce Cloak Affiliate Links <= 1.0.33 - Missing Authorization to Unauthenticated Permalink ModificationEPSS 0.7%CVE-2024-8271HIGHFOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.7%CVE-2023-4796MEDIUMBooster for WooCommerce <= 7.1.0 - Authenticated (Subscriber+) Information Disclosure via ShortcodeEPSS 0.7%CVE-2024-13342HIGHBooster for WooCommerce <= 7.2.4 - Unauthenticated Double Extension Arbitrary File UploadEPSS 0.7%CVE-2023-3125MEDIUMB2BKing <= 4.6.00 - Missing Authorization to Authenticated(Subscriber+) Price ModificationEPSS 0.7%CVE-2025-22352HIGHWordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerabilityEPSS 0.7%CVE-2025-12000MEDIUMWPFunnels <= 3.6.2 - Authenticated (Administrator+) Arbitrary File Deletion via Path TraversalEPSS 0.7%CVE-2025-13329CRITICALFile Uploader for WooCommerce <= 1.0.3 - Unauthenticated Arbitrary File Upload via add-image-dataEPSS 0.7%CVE-2023-48327HIGHWordPress WC Vendors Marketplace Plugin <= 2.4.7 is vulnerable to SQL InjectionEPSS 0.7%CVE-2022-1563MEDIUMWPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure EPSS 0.7%CVE-2022-4935HIGHWCFM Marketplace <= 3.4.11 - Missing AuthorizationEPSS 0.7%CVE-2021-34619HIGHCross-Site Request Forgery in WooCommerce Stock Manager WordPress PluginEPSS 0.7%CVE-2024-12600HIGHCustom Product Tabs Lite for WooCommerce <= 1.9.0 - Authenticated (Shop Manager+) PHP Object InjectionEPSS 0.7%CVE-2024-13487HIGHCURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price FunctionEPSS 0.7%CVE-2019-25151MEDIUMFunnel Builder <= 1.3.0 - Arbitrary Plugin ActivationEPSS 0.7%CVE-2025-10046MEDIUMELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL InejctionEPSS 0.7%CVE-2026-17581HIGHWCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template EngineEPSS 0.7%CVE-2025-2266CRITICALCheckout Mestres do WP for WooCommerce 8.6.5 - 8.7.5 - Unauthenticated Arbitrary Options UpdateEPSS 0.7%CVE-2024-13921HIGHOrder Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data ParameterEPSS 0.7%CVE-2022-2267MailChimp for Woocommerce < 2.7.1 - Subscriber+ SSRFEPSS 0.7%