Exposição de WooCommerce

Ecommerce, WordPress plugins
2.628
score de exposição
568.489
sites usam
0
em exploração
186
críticos
Análise Vexday

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2.368 resultados
CVE-2025-3743MEDIUMUpsell Funnel Builder for WooCommerce <= 3.0.0 - Unauthenticated Order ManipulationEPSS 0.4%CVE-2024-6635HIGHWooCommerce - Social Login <= 2.7.3 - Unauthenticated Authentication BypassEPSS 0.4%CVE-2025-54697HIGHWordPress Kadence WooCommerce Email Designer Plugin <= 1.5.16 - Privilege Escalation VulnerabilityEPSS 0.4%CVE-2024-3047HIGHPDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Server-Side Request ForgeryEPSS 0.4%CVE-2023-49185HIGHWordPress Doofinder for WooCommerce Plugin <= 2.1.7 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2023-32796HIGHWordPress WooCommerce Product Enquiry Plugin <= 2.3.4 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2024-9538MEDIUMShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor TemplateEPSS 0.4%CVE-2022-38141MEDIUMWordPress Sales Report Email for WooCommerce Plugin <= 2.8 is vulnerable to Broken Access ControlEPSS 0.4%CVE-2024-7027HIGHWooCommerce - PDF Vouchers <= 4.9.3 - Authentication Bypass to Voucher VendorEPSS 0.4%CVE-2024-31276MEDIUMWordPress Products, Order & Customers Export for WooCommerce plugin <= 2.0.8 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2023-6626MEDIUMProduct Enquiry for WooCommerce < 3.1 - Admin+ Stored XSSEPSS 0.4%CVE-2024-10638MEDIUMProduct Labels For Woocommerce < 1.5.11 - Admin+ SQLiEPSS 0.4%CVE-2026-9284HIGHWooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information DisclosureEPSS 0.4%CVE-2026-3688HIGHWCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role OverwriteEPSS 0.4%CVE-2024-10535MEDIUMVideo Gallery for WooCommerce <= 1.31 - Missing Authorization to Unauthenticated Limited File DeletionEPSS 0.4%CVE-2024-56290CRITICALWordPress Multiple Shipping And Billing Address For Woocommerce Plugin <= 1.2 - Unauthenticated SQL Injection vulnerabilityEPSS 0.4%CVE-2026-54849CRITICALWordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.11 - SQL Injection vulnerabilityEPSS 0.4%CVE-2024-3718MEDIUMThe Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip BoxEPSS 0.4%CVE-2024-4482MEDIUMThe Plus Addons for Elementor <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown WidgetEPSS 0.4%CVE-2026-5617HIGHLogin as User <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation via 'oclaup_original_admin' CookieEPSS 0.4%