Missing Authorization
2 records50%First: 2020. Latest: 2020.
Plugin security history
The Wordfence Intelligence dataset currently contains 4 vulnerability records associated with WooCommerce Blocks, published between 2020 and 2023.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2020 | 2 | |
| 2021 | 1 | |
| 2023 | 1 |
| Severity | Records | Share |
|---|---|---|
| High | 2 | 50% |
| Medium | 2 | 50% |
First: 2020. Latest: 2020.
First: 2021. Latest: 2021.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
11.1.25.5.15.4.15.3.25.2.15.1.15.0.14.9.24.8.14.7.14.6.14.5.34.4.34.3.14.2.14.1.14.0.13.9.13.8.13.7.23.6.13.5.13.4.13.3.13.2.13.1.13.0.12.9.12.8.12.7.22.6.22.5.163.7.1Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
3.1 | WooCommerce Blocks < 5.5 - Authenticated Blind SQL Injection | July 3, 2021 | 2.5.16, 2.6.2, 2.7.2, 2.8.1, 2.9.1, 3.0.1, 3.1.1, 3.2.1, 3.3.1, 3.4.1, 3.5.1, 3.6.1, 3.7.2, 3.8.1, 3.9.1, 4.0.1, 4.1.1, 4.2.1, 4.3.1, 4.4.3, 4.5.3, 4.6.1, 4.7.1, 4.8.1, 4.9.2, 5.0.1, 5.1.1, 5.2.1, 5.3.2, 5.4.1, 5.5.1 | High |
3.0 | WooCommerce Blocks < 5.5 - Authenticated Blind SQL Injection | July 3, 2021 | 2.5.16, 2.6.2, 2.7.2, 2.8.1, 2.9.1, 3.0.1, 3.1.1, 3.2.1, 3.3.1, 3.4.1, 3.5.1, 3.6.1, 3.7.2, 3.8.1, 3.9.1, 4.0.1, 4.1.1, 4.2.1, 4.3.1, 4.4.3, 4.5.3, 4.6.1, 4.7.1, 4.8.1, 4.9.2, 5.0.1, 5.1.1, 5.2.1, 5.3.2, 5.4.1, 5.5.1 | High |
2.9 | WooCommerce Blocks < 5.5 - Authenticated Blind SQL Injection | July 3, 2021 | 2.5.16, 2.6.2, 2.7.2, 2.8.1, 2.9.1, 3.0.1, 3.1.1, 3.2.1, 3.3.1, 3.4.1, 3.5.1, 3.6.1, 3.7.2, 3.8.1, 3.9.1, 4.0.1, 4.1.1, 4.2.1, 4.3.1, 4.4.3, 4.5.3, 4.6.1, 4.7.1, 4.8.1, 4.9.2, 5.0.1, 5.1.1, 5.2.1, 5.3.2, 5.4.1, 5.5.1 | High |
2.8 | WooCommerce Blocks < 5.5 - Authenticated Blind SQL Injection | July 3, 2021 | 2.5.16, 2.6.2, 2.7.2, 2.8.1, 2.9.1, 3.0.1, 3.1.1, 3.2.1, 3.3.1, 3.4.1, 3.5.1, 3.6.1, 3.7.2, 3.8.1, 3.9.1, 4.0.1, 4.1.1, 4.2.1, 4.3.1, 4.4.3, 4.5.3, 4.6.1, 4.7.1, 4.8.1, 4.9.2, 5.0.1, 5.1.1, 5.2.1, 5.3.2, 5.4.1, 5.5.1 | High |
2.7-2.7.1 | WooCommerce Blocks < 5.5 - Authenticated Blind SQL Injection | July 3, 2021 | 2.5.16, 2.6.2, 2.7.2, 2.8.1, 2.9.1, 3.0.1, 3.1.1, 3.2.1, 3.3.1, 3.4.1, 3.5.1, 3.6.1, 3.7.2, 3.8.1, 3.9.1, 4.0.1, 4.1.1, 4.2.1, 4.3.1, 4.4.3, 4.5.3, 4.6.1, 4.7.1, 4.8.1, 4.9.2, 5.0.1, 5.1.1, 5.2.1, 5.3.2, 5.4.1, 5.5.1 | High |
2.6-2.6.1 | WooCommerce Blocks < 5.5 - Authenticated Blind SQL Injection | July 3, 2021 | 2.5.16, 2.6.2, 2.7.2, 2.8.1, 2.9.1, 3.0.1, 3.1.1, 3.2.1, 3.3.1, 3.4.1, 3.5.1, 3.6.1, 3.7.2, 3.8.1, 3.9.1, 4.0.1, 4.1.1, 4.2.1, 4.3.1, 4.4.3, 4.5.3, 4.6.1, 4.7.1, 4.8.1, 4.9.2, 5.0.1, 5.1.1, 5.2.1, 5.3.2, 5.4.1, 5.5.1 | High |
*-2.5.15 | WooCommerce Blocks < 5.5 - Authenticated Blind SQL Injection | July 3, 2021 | 2.5.16, 2.6.2, 2.7.2, 2.8.1, 2.9.1, 3.0.1, 3.1.1, 3.2.1, 3.3.1, 3.4.1, 3.5.1, 3.6.1, 3.7.2, 3.8.1, 3.9.1, 4.0.1, 4.1.1, 4.2.1, 4.3.1, 4.4.3, 4.5.3, 4.6.1, 4.7.1, 4.8.1, 4.9.2, 5.0.1, 5.1.1, 5.2.1, 5.3.2, 5.4.1, 5.5.1 | High |
[*, 3.7.1) | WooCommerce Blocks <= 3.7.0 - Authorization Bypass | November 5, 2020 | 3.7.1 | High |
[*, 3.7.1) | WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation | November 5, 2020 | 3.7.1 | Medium |
Selected source records
Published: November 15, 2023
Published: July 3, 2021
Published: November 5, 2020
Published: November 5, 2020
Published: July 3, 2021
Published: November 5, 2020
Published: November 5, 2020
Published: November 15, 2023
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.