Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

Clear filters

44 vulnerability records

MediumCVE-2026-3589

WooCommerce < 10.5.3 - Cross-Site Request Forgery

WooCommerce: Currently marked unpatched

Affected versions: [*, 10.5.3)

Vulnerability type: CWE-352 Cross-Site Request Forgery (CSRF)

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 10.5.3 (exclusive). This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.

WooCommerce

Affected versions: [*, 10.5.3)

Patched versions: 10.5.3

Researcher credit: oolongeya

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
March 10, 2026
CVSS
4.3
MediumCVE-2025-15033

WooCommerce <= 10.4.2 - Authenticated (Subscriber+) Information Exposure

WooCommerce: Currently marked unpatched

Affected versions: 10.0-10.0.4; 10.1-10.1.2; 10.2-10.2.2; 10.3-10.3.6; 8.1-8.1.2; 8.2-8.2.3; 8.3-8.3.2; 8.4-8.4.1

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.4.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

WooCommerce

Affected versions: 10.0-10.0.4; 10.1-10.1.2; 10.2-10.2.2; 10.3-10.3.6; 8.1-8.1.2; 8.2-8.2.3; 8.3-8.3.2; 8.4-8.4.1; 8.5-8.5.3; 8.6-8.6.2; 8.7-8.7.1; 8.8-8.8.5; 8.9-8.9.3; 9.0-9.0.2; 9.1-9.1.4; 9.2-9.2.3; 9.3-9.3.4; 9.4-9.4.3; 9.5-9.5.2; 9.6-9.6.2; 9.7-9.7.1; 9.8-9.8.5; 9.9-9.9.5

Patched versions: 10.0.5, 10.1.3, 10.2.3, 10.3.7, 8.1.3, 8.2.4, 8.3.3, 8.4.2, 8.5.4, 8.6.3, 8.7.2, 8.8.6, 8.9.4, 9.0.3, 9.1.5, 9.2.4, 9.3.5, 9.4.4, 9.5.3, 9.6.3, 9.7.2, 9.8.6, 9.9.6

Researcher credit: Peter Stöckli, Man Yue Mo

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 22, 2025
CVSS
4.3
MediumCVE-2025-49042

WooCommerce <= 10.0.2 - Authenticated (Shop manager+) Stored Cross-Site Scripting

WooCommerce: Currently marked unpatched

Affected versions: *-10.0.2

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

WooCommerce

Affected versions: *-10.0.2

Patched versions: 10.0.3

Researcher credit: SavPhill (Savphill)

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 29, 2025
CVSS
4.4
MediumCVE-2025-5062

WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting

WooCommerce: Currently marked unpatched

Affected versions: *-9.3.2; 9.4-9.4.2

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

WooCommerce

Affected versions: *-9.3.2; 9.4-9.4.2

Patched versions: 9.3.4, 9.4.3

Researcher credit: Antonio Rocco Spataro

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
May 21, 2025
CVSS
6.1
MediumCVE-2025-26762

WooCommerce <= 9.7.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting

WooCommerce: Currently marked unpatched

Affected versions: *-9.7.0

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

WooCommerce

Affected versions: *-9.7.0

Patched versions: 9.7.1

Researcher credit: SavPhill (Savphill)

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
March 12, 2025
CVSS
4.4
MediumCVE-2024-9944

WooCommerce <= 9.0.2 - Unauthenticated HTML Injection

WooCommerce: Currently marked unpatched

Affected versions: *-9.0.2

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.

WooCommerce

Affected versions: *-9.0.2

Patched versions: 9.1.0

Researcher credit: drop

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 14, 2024
CVSS
5.3
MediumCVE-2024-39666

WooCommerce <= 9.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

WooCommerce: Currently marked unpatched

Affected versions: *-9.1.2

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.

WooCommerce

Affected versions: *-9.1.2

Patched versions: 9.1.3

Researcher credit: stealthcopter

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
August 16, 2024
CVSS
4.4
LowCVE-2024-35777

WooCommerce <= 8.9.2 - Authenticated (Shop Manager+) Content Injection

WooCommerce: Currently marked unpatched

Affected versions: *-8.9.2

Vulnerability type: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to content injection in all versions up to, and including, 8.9.2. This is due to the plugin not properly restricting/validating content. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inject arbitrary content.

WooCommerce

Affected versions: *-8.9.2

Patched versions: 9.0.0

Researcher credit: SavPhill (Savphill)

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 27, 2024
CVSS
2.7
MediumCVE-2024-37297

WooCommerce 8.8.0 - 8.9.2 - Reflected Cross-Site Scripting via Order Attribution

WooCommerce: Currently marked unpatched

Affected versions: 8.8.0-8.8.4; 8.9.0-8.9.2

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via order attribution cookies in versions 8.8.0 to 8.8.4 and 8.9.0 to 8.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

WooCommerce

Affected versions: 8.8.0-8.8.4; 8.9.0-8.9.2

Patched versions: 8.8.5, 8.9.3

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 10, 2024
CVSS
6.1
MediumCVE-2024-22155

WooCommerce <= 8.5.2 - Cross-Site Request Forgery

WooCommerce: Currently marked unpatched

Affected versions: *-8.5.2

Vulnerability type: CWE-352 Cross-Site Request Forgery (CSRF)

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

WooCommerce

Affected versions: *-8.5.2

Patched versions: 8.6.0

Researcher credit: Dhabaleshwar Das

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 5, 2024
CVSS
4.3
Medium

WooCommerce < 8.4.0 - Reflected Cross-Site Scripting

WooCommerce: Currently marked unpatched

Affected versions: [*, 8.4.0)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions before 8.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. IMPORTANT: There was a miscommunication and error in this vulnerability record where we initially reported version 8.5.0 as patched, while 8.4.0 was still vulnerable. This issue was patched in version 8.4.0 and only affects versions up to 8.3.0. Please rest assured knowing you can update the plugin to version 8.4.0 and this issue will be patched.

WooCommerce

Affected versions: [*, 8.4.0)

Patched versions: 8.4.0

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
January 12, 2024
CVSS
6.1
MediumCVE-2023-52222

WooCommerce <= 8.2.2 - Cross-Site Request Forgery

WooCommerce: Currently marked unpatched

Affected versions: *-8.2.2

Vulnerability type: CWE-352 Cross-Site Request Forgery (CSRF)

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

WooCommerce

Affected versions: *-8.2.2

Patched versions: 8.3.0

Researcher credit: Rafie Muhammad

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
January 5, 2024
CVSS
4.3
MediumCVE-2023-47777

WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image alt Attribute

WooCommerce: Currently marked unpatchedWooCommerce Blocks: Currently marked unpatched

Affected versions: *-8.1.1; *-11.1.1

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a featured image 'alt' attribute in versions up to, and including, 8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The WooCommerce Blocks plugin for WordPress is vulnerable to the same issue in versions up to, and including, 11.1.1.

WooCommerce

Affected versions: *-8.1.1

Patched versions: 8.2.0

WooCommerce Blocks

Affected versions: *-11.1.1

Patched versions: 11.1.2

Researcher credit: Rafie Muhammad

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 15, 2023
CVSS
6.4
MediumCVE-2023-7320

WooCommerce <= 7.8.2 - Sensitive Information Exposure

WooCommerce: Currently marked unpatched

Affected versions: *-7.8.2

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information including PII(Personal Identifiable Information).

WooCommerce

Affected versions: *-7.8.2

Patched versions: 7.9.0

Researcher credit: osama-hamad

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
September 11, 2023
CVSS
5.3
Medium

WooCommerce <= 7.0.0 - Authenticated(Shop Manager+) Sensitive Information Exposure

WooCommerce: Currently marked unpatched

Affected versions: *-7.0.0

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.0. This can allow authenticated attackers with Shop Manager privileges or above to extract sensitive user metadata including session tokens.

WooCommerce

Affected versions: *-7.0.0

Patched versions: 7.0.1

Researcher credit: David Anderson

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
September 11, 2023
CVSS
4.9
MediumCVE-2022-2099

WooCommerce <= 6.5.1 - Authenticated (Admin+) HTML Injection

WooCommerce: Currently marked unpatched

Affected versions: [*, 6.6.0)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Stored HTML Injection via payment gateway titles in versions up to 6.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with high-level capabilities, such as a Store Manager, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

WooCommerce

Affected versions: [*, 6.6.0)

Patched versions: 6.6.0

Researcher credit: Taurus Omar

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 20, 2022
CVSS
5.5
Medium

WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Information Disclosure

WooCommerce: Currently marked unpatchedWooCommerce Admin: Currently marked unpatched

Affected versions: [*, 4.0); [4.0, 4.0.3); [4.1, 4.1.3); [4.2, 4.2.4); [4.3, 4.3.5); [4.4, 4.4.3); [4.5, 4.5.4); [4.6, 4.6.4)

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

The WooCommerce and WooCommerce Admin plugins for WordPress are vulnerable to Sensitive Data Exposure in versions up to 5.7.0 for WooCommerce and 2.6.4 for WooCommerce Admin due to insufficient protection of analytic report storage in the directory they are stored. This makes it possible for attackers to extract sensitive data related to report analytics on certain host configurations.

WooCommerce

Affected versions: [*, 4.0); [4.0, 4.0.3); [4.1, 4.1.3); [4.2, 4.2.4); [4.3, 4.3.5); [4.4, 4.4.3); [4.5, 4.5.4); [4.6, 4.6.4); [4.7, 4.7.3); [4.8, 4.8.2); [4.9, 4.9.4); [5.0, 5.0.2); [5.1, 5.1.2); [5.2, 5.2.4); [5.3, 5.3.2); [5.4, 5.4.3); [5.5, 5.5.3); [5.6, 5.6.1)

Patched versions: 4.0.3, 4.1.3, 4.2.4, 4.3.5, 4.4.3, 4.5.4, 4.6.4, 4.7.3, 4.8.2, 4.9.4, 5.0.2, 5.1.2, 5.2.4, 5.3.2, 5.4.3, 5.5.3, 5.6.1, 5.7.0

WooCommerce Admin

Affected versions: *-1.0; [1.0, 1.0.4); [1.1, 1.1.4); [1.2, 1.2.5); [1.3, 1.3.3); [1.4, 1.4.1); [1.5, 1.5.1); [1.6, 1.6.4); [1.7, 1.7.4); [1.8, 1.8.4); [1.9, 1.9.1); [2.0, 2.0.4); [2.1, 2.1.6); [2.2, 2.2.7); [2.3, 2.3.2); [2.4, 2.4.5); [2.5, 2.5.2); [2.6, 2.6.4)

Patched versions: 1.0.4, 1.1.4, 1.2.5, 1.3.3, 1.4.1, 1.5.1, 1.6.4, 1.7.4, 1.8.4, 1.9.1, 2.0.4, 2.1.6, 2.2.7, 2.3.2, 2.4.5, 2.5.2, 2.6.4

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 10, 2022
CVSS
6.5
Medium

WooCommerce < 6.3.1 - Unauthorized Order Status Change

WooCommerce: Currently marked unpatched

Affected versions: [3.5, 3.5.10); [3.6, 3.6.7); [3.7, 3.7.3); [3.8, 3.8.3); [3.9, 3.9.5); [4.0, 4.0.4); [4.1, 4.1.4); [4.2, 4.2.5)

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce check on the PayPal order updates functionality in versions up to, and including, 6.3.0. This makes it possible for authenticated attackers to change the status of arbitrary orders that have been created with PayPal.

WooCommerce

Affected versions: [3.5, 3.5.10); [3.6, 3.6.7); [3.7, 3.7.3); [3.8, 3.8.3); [3.9, 3.9.5); [4.0, 4.0.4); [4.1, 4.1.4); [4.2, 4.2.5); [4.3, 4.3.6); [4.4, 4.4.4); [4.5, 4.5.5); [4.6, 4.6.5); [4.7, 4.7.4); [4.8, 4.8.3); [4.9, 4.9.5); [5.0, 5.0.3); [5.1, 5.1.3); [5.2, 5.2.5); [5.3, 5.3.3); [5.4, 5.4.4); [5.5, 5.5.4); [5.6, 5.6.2); [5.7, 5.7.2); [5.8, 5.8.1); [5.9, 5.9.1); [6.0, 6.0.1); [6.1, 6.1.2); [6.2, 6.2.2); [6.3, 6.3.1)

Patched versions: 3.5.10, 3.6.7, 3.7.3, 3.8.3, 3.9.5, 4.0.4, 4.1.4, 4.2.5, 4.3.6, 4.4.4, 4.5.5, 4.6.5, 4.7.4, 4.8.3, 4.9.5, 5.0.3, 5.1.3, 5.2.5, 5.3.3, 5.4.4, 5.5.4, 5.6.2, 5.7.2, 5.8.1, 5.9.1, 6.0.1, 6.1.2, 6.2.2, 6.3.1

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
March 10, 2022
CVSS
4.3
MediumCVE-2022-0775

WooCommerce <= 6.2.0 - Incorrect Authorization Checks on REST API Endpoints

WooCommerce: Currently marked unpatched

Affected versions: *-6.2.0

Vulnerability type: CWE-285 Improper Authorization

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on the /wc/v2/products/ REST API in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers with minimal permissions such as a subscriber to delete, edit, and read arbitrary comments and reviews.

WooCommerce

Affected versions: *-6.2.0

Patched versions: 6.2.1

Researcher credit: Krzysztof Zając

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 22, 2022
CVSS
5.4
High

WooCommerce <= 6.2.0 - Path Traversal via Tax Importer

WooCommerce: Currently marked unpatched

Affected versions: *-6.2.0

Vulnerability type: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to path traversal via the 'file_url' parameter found in the importers functionality in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers, with high-level permissions such as an administrator, to access files outside of the intended directory when performing an import.

WooCommerce

Affected versions: *-6.2.0

Patched versions: 6.2.1

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 22, 2022
CVSS
7.2
HighCVE-2021-32790

WooCommerce < 5.5 - Authenticated Blind SQL Injection

WooCommerce: Currently marked unpatched

Affected versions: [*, 3.3); 3.3-3.3.5; 3.4-3.4.7; 3.5-3.5.8; 3.6-3.6.5; 3.7-3.7.1; 3.8-3.8.1; 3.9-3.9.3

Vulnerability type: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Affected software, patched versions and attribution

Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 5.5. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `/wp-json/wc/v3/webhooks`, `/wp-json/wc/v2/webhooks` and other webhook listing API. Read-only SQL queries can be executed using this exploit, while data will not be returned, by carefully crafting `search` parameter information can be disclosed using timing and related attacks. Version 3.3.6 is the earliest version of Woocommerce with a patch for this vulnerability. There are no known workarounds other than upgrading.

WooCommerce

Affected versions: [*, 3.3); 3.3-3.3.5; 3.4-3.4.7; 3.5-3.5.8; 3.6-3.6.5; 3.7-3.7.1; 3.8-3.8.1; 3.9-3.9.3; 4.0-4.0.1; 4.1-4.1.1; 4.2-4.2.2; 4.3-4.3.3; 4.4-4.4.1; 4.5-4.5.2; 4.6-4.6.2; 4.7-4.7.1; 4.8; 4.9-4.9.2; 5.0; 5.1; 5.2-5.2.2; 5.3; 5.4-5.4.1; 5.5

Patched versions: 3.3.6, 3.4.8, 3.5.9, 3.6.6, 3.7.2, 3.8.2, 3.9.4, 4.0.2, 4.1.2, 4.2.3, 4.3.4, 4.4.2, 4.5.3, 4.6.3, 4.7.2, 4.8.1, 4.9.3, 5.0.1, 5.1.1, 5.2.3, 5.3.1, 5.4.2, 5.5.1, 5.5.2

Researcher credit: Josh (jl-dos)

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
July 13, 2021
CVSS
8.8
MediumCVE-2021-24323

WooCommerce <= 5.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting

WooCommerce: Currently marked unpatched

Affected versions: [*, 5.2.0)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Additional tax classes' field when the tax functionality of WooCommerce is enabled in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

WooCommerce

Affected versions: [*, 5.2.0)

Patched versions: 5.2.0

Researcher credit: R3N0

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 21, 2021
CVSS
4.8
Medium

WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation

WooCommerce: Currently marked unpatchedWooCommerce Blocks: Currently marked unpatched

Affected versions: [*, 4.6.2); [*, 3.7.1)

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to unauthorized user account creation during checkout even when the “Allow customers to create an account during checkout” setting is disabled. was disabled due to missing authorization checks in versions up to and including 4.6.1. The WooCommerce Blocks plugin for WordPress is vulnerable to the same issue in versions up to, and including, 3.7.1.

WooCommerce

Affected versions: [*, 4.6.2)

Patched versions: 4.6.2

WooCommerce Blocks

Affected versions: [*, 3.7.1)

Patched versions: 3.7.1

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 5, 2020
CVSS
6.5
Medium

WooCommerce <= 4.2.0 - Reflected Cross-Site Scripting

WooCommerce: Currently marked unpatched

Affected versions: [*, 4.2.1)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing sanitization and escaping in SelectWoo, that makes it possible for attackers to inject arbitrary web scripts. This affects versions up to 4.2.1.

WooCommerce

Affected versions: [*, 4.2.1)

Patched versions: 4.2.1

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 22, 2020
CVSS
6.1
High

WooCommerce <= 4.0.4 - Unauthorized Post Meta Creation/Modification

WooCommerce: Currently marked unpatched

Affected versions: [*, 4.1.0)

Vulnerability type: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Affected software, patched versions and attribution

The WooCommerce plugin for WordPress is vulnerable to arbitrary product meta data creation/overwriting due to a lack of escaping and validation on the post meta data being supplied during product duplication in versions up to, and including 4.0.4. This makes it possible for authenticated attackers, with product duplicating capabilities, to modify post meta that could potential be used to achieve remote code execution.

WooCommerce

Affected versions: [*, 4.1.0)

Patched versions: 4.1.0

Researcher credit: Slavco Mihajloski

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
May 5, 2020
CVSS
8.8

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.