Exposição de WooCommerce

Ecommerce, WordPress plugins
2.628
score de exposição
568.489
sites usam
0
em exploração
186
críticos
Análise Vexday

O WooCommerce acumula 2.037 CVEs catalogadas, volume expressivo que reflete sua ampla adoção e superfície de ataque — das quais 158 são de severidade crítica e 137 surgiram nos últimos 90 dias, indicando ritmo elevado de descoberta recente. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma entrada confirmada no momento, embora isso não elimine o risco operacional dado o alto volume de falhas críticas acumuladas. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que exige atenção contínua em ambientes com múltiplos plugins e temas integrados. O CVE-2023-28121 merece prioridade imediata: seu score EPSS de 0,87 indica probabilidade muito elevada de exploração ativa nos próximos 30 dias, tornando-o o principal vetor de risco a ser tratado em qualquer plano de remediação.

CVEs

2.368 resultados
CVE-2025-12115HIGHWPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price AlterationEPSS 0.3%CVE-2026-4432MEDIUMYITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOREPSS 0.3%CVE-2025-32241MEDIUMWordPress Official CleverReach WooCommerce Integration plugin <= 3.4.6 - CSRF to Settings Change vulnerabilityEPSS 0.3%CVE-2026-77695MEDIUMWoo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and ManipulationEPSS 0.3%CVE-2026-14315MEDIUMPixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event SubmissionEPSS 0.3%CVE-2025-14891MEDIUMCustomer Reviews for WooCommerce <= 5.93.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via displayName ParameterEPSS 0.3%CVE-2024-1857MEDIUMUltimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates <= 2.6.6 - Missing Authorization to Unauthenticated Information ExposureEPSS 0.3%CVE-2024-0767MEDIUMEnvo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Cross-Site Request Forgery via ajax_plugin_activationEPSS 0.3%CVE-2025-5285MEDIUMProduct Subtitle for WooCommerce <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via htmlTag ParameterEPSS 0.3%CVE-2025-14034MEDIUMilGhera Support System for WooCommerce <= 1.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket DeletionEPSS 0.3%CVE-2025-26888MEDIUMWordPress WooCommerce Multilingual & Multicurrency plugin <= 5.3.8 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-1943MEDIUMYayMail <= 4.3.2 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via Template ElementsEPSS 0.3%CVE-2025-6201MEDIUMPixel Manager for WooCommerce (PRO) <= 1.49.0 - Authenticated (Contributor+) Cross-Site Scripting via ShortcodeEPSS 0.3%CVE-2025-11894MEDIUMShelf Planner <= 2.8.1 - Missing Authorization to Unauthenticated Settings UpdateEPSS 0.3%CVE-2024-12210MEDIUMPrint Invoice & Delivery Notes for WooCommerce <= 5.4.0 - Missing Authorization to Authenticated (Subscriber+) Logo DeletionEPSS 0.3%CVE-2022-45376MEDIUMWordPress Side Cart Woocommerce (Ajax) Plugin < 2.1 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2024-49640HIGHWordPress ACL Floating Cart for WooCommerce plugin <= 0.9 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-14339MEDIUMweMail <= 2.0.7 - Missing Authorization to Unauthenticated Form DeletionEPSS 0.3%CVE-2025-31879MEDIUMWordPress Barcode Generator for WooCommerce plugin <= 2.0.4 - Settings Change vulnerabilityEPSS 0.3%CVE-2023-35091MEDIUMWordPress WooCommerce Stock Manager Plugin <= 2.10.0 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%