Exposição de WooCommerce

Ecommerce, WordPress plugins
2.628
score de exposição
568.489
sites usam
0
em exploração
186
críticos
Análise Vexday

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2.368 resultados
CVE-2024-3608MEDIUMProduct Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment DeletionEPSS 0.6%CVE-2025-54713CRITICALWordPress Taxi Booking Manager for WooCommerce plugin <= 1.3.0 - Broken Authentication vulnerabilityEPSS 0.6%CVE-2024-1795HIGHHUSKY – Products Filter for WooCommerce Professional <= 1.3.5.2 - Authenticated (Contributor+) SQL InjectionEPSS 0.6%CVE-2024-13472HIGHWooCommerce Product Table Lite <= 3.9.4 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site ScriptingEPSS 0.6%CVE-2024-1807MEDIUMProduct Sort and Display for WooCommerce <= 2.4.1 - Missing AuthorizationEPSS 0.6%CVE-2026-12994MEDIUMWCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage ControllerEPSS 0.6%CVE-2023-2450MEDIUMThe FiboSearch - AJAX Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versionEPSS 0.6%CVE-2023-41803MEDIUMWordPress BitPay Checkout for WooCommerce plugin <= 4.1.0 - Broken Access Control vulnerabilityEPSS 0.6%CVE-2023-25026MEDIUMWordPress PayPal Brasil para WooCommerce plugin <= 1.4.2 - Broken Access Control vulnerabilityEPSS 0.6%CVE-2024-1047MEDIUMThemeIsle SDK <= Various Versions - Missing AuthorizationEPSS 0.6%CVE-2025-48129CRITICALWordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin <= 2.4.37 - Privilege Escalation VulnerabilityEPSS 0.6%CVE-2023-52215CRITICALWordPress Barcode Scanner with Inventory & Order Manager Plugin <=1.5.1 is vulnerable to SQL InjectionEPSS 0.6%CVE-2026-1929HIGHAdvanced Woo Labels <= 2.37 - Authenticated (Contributor+) Remote Code Execution via 'callback' ParameterEPSS 0.6%CVE-2023-47244MEDIUMWordPress Email Marketing for WooCommerce by Omnisend Plugin <= 1.13.8 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2024-49658CRITICALWordPress Woocommerce Custom Profile Picture plugin <= 1.0 - Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2022-3536HIGHRole Based Pricing for WooCommerce < 1.6.3 - Subscriber+ PHAR DeserializationEPSS 0.6%CVE-2024-6560MEDIUMAddonify – Quick View For WooCommerce <= 1.2.16 - Unauthenticated Full Path DislcosureEPSS 0.6%CVE-2024-30230HIGHWordPress PDF Invoices and Packing Slips For WooCommerce plugin <= 1.3.7 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-9662HIGHRecover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion via 'tpf' ParameterEPSS 0.6%CVE-2024-13797HIGHPressMart - Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.5%