SecAlerts
W

WooCommerce

Security Risk Profile

45
/100
medium

Security Risk Score

Comprehensive risk assessment based on 291 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 4, 2017 to present

291
Total CVEs
127
Critical+High
2
Exploited
90
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
90
Critical/High
Risk Level
45/100
medium
⚠️ 2 Active Exploits🆕 1Fresh (<7d)📈 11 in Last 30 Days

Severity Distribution

Critical
27
High
100
Medium
162
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
37

Age Distribution

Common Weaknesses (CWE)

1
XSS
74
2
CSRF
32
3
Path Traversal
18
4
SQL Injection
16
5
Malicious File Upload
14

Most Affected Products

1. WooCommerce WooCommerce WordPress40
2. WooCommerce Customer Reviews for WooCommerce7
3. weDevs Wp Erp Wordpress7
4. WooCommerce Customers Manager7
5. Vanquish Woocommerce Customers Manager Wordpress7

Recent Vulnerabilities

See more →
CVE-2026-92400
CVSS 5.3medium

Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion

Sep 21, 2026🔧 No Patch
CVE-2026-87831
CVSS 4.3medium

Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field

Sep 17, 2026🔧 No Patch
CVE-2026-87854
CVSS 5.3medium

Subscriptions for WooCommerce < 2.0.3 - Unauthenticated Subscription Data Disclosure via REST API Secret Key Bypass

Sep 16, 2026🔧 No Patch
CVE-2026-81431
CVSS 7.2high

Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Unvalidated tgwcfb_id

Sep 10, 2026🔧 No Patch
CVE-2026-19436
CVSS 7.5high

Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation via Discounted Purchase

Sep 10, 2026🔧 No Patch
CVE-2026-15019
CVSS 7.5high

Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path Segment

Sep 10, 2026🔧 No Patch
CVE-2026-75861
CVSS 6.5medium

Ultimate Gift Cards for WooCommerce < 3.2.10 - Subscriber+ Gift Card Theft and Destruction via Unauthorized Redemption

Sep 9, 2026🔧 No Patch
CVE-2026-81282
CVSS 6.5medium

WordPress Product Variations Swatches for WooCommerce plugin <= 1.1.18 - Cross Site Scripting (XSS) vulnerability

Sep 3, 2026🔧 No Patch
CVE-2026-15369
CVSS 9.8critical

Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout

Aug 29, 2026🔧 No Patch
CVE-2026-6176
CVSS 7.2high

Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form

Aug 28, 2026🔧 No Patch

Monitor WooCommerce in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

WooCommerce Security Vulnerabilities & Risk Score | 291 CVEs | SecAlerts - SecAlerts