Exposição de WooCommerce

Ecommerce, WordPress plugins
2.628
score de exposição
568.489
sites usam
0
em exploração
186
críticos
Análise Vexday

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2.368 resultados
CVE-2023-3507MEDIUMWooCommerce Pre-Orders < 2.0.3 - Arbitrary Pre-Order Canceling via CSRFEPSS 0.3%CVE-2024-13735MEDIUMHurryTimer <= 2.11.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Campaign NameEPSS 0.3%CVE-2024-24886MEDIUMWordPress Product Labels For Woocommerce Plugin <= 1.5.3 is vulnerable to Cross Site Scripting (XSS)EPSS 0.3%CVE-2026-1926MEDIUMSubscriptions for WooCommerce <= 1.9.2 - Missing Authorization to Unauthenticated Arbitrary Subscription CancellationEPSS 0.3%CVE-2026-19800MEDIUMMail Mint <= 1.31.0 - Authenticated (Custom+) SQL Injection via 'status' ParameterEPSS 0.3%CVE-2025-26928MEDIUMWordPress Order Limit for WooCommerce plugin <= 3.0.2 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-30917HIGHWordPress SKU Generator for WooCommerce plugin <= 1.6.2 - Reflected Cross Site Scripting (XSS) VulnerabilityEPSS 0.3%CVE-2025-30837HIGHWordPress WooCommerce Fattureincloud plugin <= 2.6.7 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-32512HIGHWordPress Revamp CRM for WooCommerce plugin <= 1.1.2 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-30924HIGHWordPress Primer MyData for Woocommerce plugin < 4.2.4 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-30579HIGHWordPress Pesapal Gateway for Woocommerce plugin <= 2.1.0 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-32552HIGHWordPress MSRP (RRP) Pricing for WooCommerce Plugin <= 1.8.1 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2026-24562MEDIUMWordPress Ryviu – Product Reviews for WooCommerce plugin <= 3.1.26 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-1722MEDIUMWCFM Marketplace <= 3.7.0 - Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request CreationEPSS 0.3%CVE-2023-48284MEDIUMWordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2026-85038MEDIUMB2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role SelectionEPSS 0.3%CVE-2026-12966MEDIUMDirect Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX ActionsEPSS 0.3%CVE-2026-92435MEDIUMMailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST APIEPSS 0.3%CVE-2026-82305MEDIUMYITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_titleEPSS 0.3%CVE-2026-1831LOWYayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and ActivationEPSS 0.3%