Software
woocommerce
Aggregate across all detected versions
Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
23
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2017-18356 | 8.8 | N/A | In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at l... |
| CVE-2019-20891 | 8.8 | N/A | WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS... |
| CVE-2018-20714 | 8.1 | N/A | The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of wooco... |
| CVE-2017-17058 | 7.5 | N/A | The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, whic... |
| CVE-2018-20782 | 7.5 | N/A | The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages. |
| CVE-2023-47777 | 6.5 | N/A | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allo... |
| CVE-2023-25788 | 6.3 | N/A | Cross-Site Request Forgery (CSRF) vulnerability in Saphali Saphali Woocommerce Lite plugin <= 1.8.13 versions. |
| CVE-2015-2329 | 6.1 | N/A | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via... |
| CVE-2019-9168 | 6.1 | N/A | WooCommerce before 3.5.5 allows XSS via a Photoswipe caption. |
| CVE-2025-5062 | 6.1 | N/A | The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including... |
| CVE-2023-32575 | 5.9 | N/A | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin <= 1.3.25 versions. |
| CVE-2024-37297 | 5.4 | N/A | WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor... |
| CVE-2020-29156 | 5.3 | N/A | The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_sta... |
| CVE-2024-9944 | 5.3 | N/A | The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutral... |
| CVE-2024-1310 | 4.9 | N/A | The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g.... |
| CVE-2021-32790 | 4.9 | N/A | Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin betwee... |
| CVE-2024-1310 | 4.9 | N/A | The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g.... |
| CVE-2016-10112 | 4.8 | N/A | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web... |
| CVE-2021-24323 | 4.8 | N/A | When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high... |
| CVE-2022-2099 | 4.8 | N/A | The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles |
| CVE-2015-2069 | 4.3 | MEDIUM | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML vi... |
| CVE-2022-0775 | 4.3 | N/A | The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as... |
| CVE-2023-52222 | 4.3 | N/A | Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2. |