Exposição de WooCommerce

Ecommerce, WordPress plugins
2.628
score de exposição
568.489
sites usam
0
em exploração
186
críticos
Análise Vexday

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2.368 resultados
CVE-2024-9189MEDIUMEU/UK VAT Manager for WooCommerce <= 2.12.12 - Missing AuthorizationEPSS 0.5%CVE-2021-4391MEDIUMUltimate Gift Cards for WooCommerce <= 2.1.1 - Cross-Site Request Forgery BypassEPSS 0.5%CVE-2025-28955HIGHWordPress Easy Video Player Wordpress & WooCommerce plugin <= 10.0 - Arbitrary File Download VulnerabilityEPSS 0.5%CVE-2024-33944MEDIUMWordPress WooCommerce AWeber Newsletter Subscription plugin <= 4.0.2 - Unauthenticated Access Token Change/Reset vulnerabilityEPSS 0.5%CVE-2026-6072MEDIUMOliver POS <= 2.4.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to 'OliverAuth' HeaderEPSS 0.5%CVE-2024-0251MEDIUMAdvanced Woo Search <= 2.96 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2023-4376MEDIUMSerial Codes Generator and Validator with WooCommerce Support < 2.4.15 - Admin+ Stored XSSEPSS 0.5%CVE-2022-4000MEDIUMWooCommerce Shipping - DPD baltic < 1.2.11 - Admin+ Stored XSSEPSS 0.5%CVE-2024-13638MEDIUMOrder Attachments for WooCommerce <= 2.5.1 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2026-9028MEDIUMCorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Unauthenticated Arbitrary Order Cancellation via 'order_number' ParameterEPSS 0.5%CVE-2026-11360MEDIUMAdvanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager+) SQL Injection via 'sort_direction' ParameterEPSS 0.5%CVE-2023-41132MEDIUMWordPress Category Slider for WooCommerce plugin <= 1.4.15 - Broken Access Control vulnerabilityEPSS 0.5%CVE-2025-69004HIGHWordPress Bajaar - Highly Customizable WooCommerce WordPress Theme theme <= 2.1.0 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2022-44633MEDIUMWordPress YITH WooCommerce Gift Cards Premium plugin <= 3.23.1 - Unauth. Gift Card Creation Leading to Stored XSS vulnerabilityEPSS 0.5%CVE-2024-13641MEDIUMReturn Refund and Exchange For WooCommerce <= 4.4.5 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2026-15349MEDIUMERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX HandlerEPSS 0.5%CVE-2026-14500MEDIUMBulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Read via 'csv_url' ParameterEPSS 0.5%CVE-2022-4791MEDIUMProduct Slider and Carousel with Category for WooCommerce < 2.8 - Contributor+ Stored XSS via ShortcodeEPSS 0.5%CVE-2022-4629MEDIUMProduct Slider for WooCommerce < 2.6.4 - Contributor+ Stored XSS in ShortcodeEPSS 0.5%CVE-2026-11987MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' ParameterEPSS 0.5%