SecAlerts
W

WooCommerce

Security Risk Profile

47
/100
medium

Security Risk Score

Comprehensive risk assessment based on 283 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 4, 2017 to present

283
Total CVEs
124
Critical+High
2
Exploited
87
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
87
Critical/High
Risk Level
47/100
medium
⚠️ 2 Active Exploits🆕 2Fresh (<7d)📈 10 in Last 30 Days

Severity Distribution

Critical
27
High
97
Medium
157
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
37

Age Distribution

Common Weaknesses (CWE)

1
XSS
73
2
CSRF
32
3
Path Traversal
17
4
SQL Injection
16
5
Malicious File Upload
14

Most Affected Products

1. WooCommerce WooCommerce WordPress40
2. WooCommerce Customer Reviews for WooCommerce7
3. weDevs Wp Erp Wordpress7
4. WooCommerce Customers Manager7
5. Vanquish Woocommerce Customers Manager Wordpress7

Recent Vulnerabilities

See more →
CVE-2026-15369
CVSS 9.8critical

Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout

Aug 29, 2026🔧 No Patch
CVE-2026-6176
CVSS 7.2high

Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form

Aug 28, 2026🔧 No Patch
CVE-2026-18884
CVSS 7.5high

WooCommerce Lottery <= 2.2.9 - Unauthenticated Time-Based SQL Injection via 'orderby' and 'order' Parameters

Aug 26, 2026🔧 No Patch
CVE-2026-14853
CVSS 4.3medium

WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization

Aug 23, 2026🔧 No Patch
CVE-2026-77264
CVSS 9.8critical

Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure

Aug 21, 2026🔧 No Patch
CVE-2026-16621
CVSS 5.3medium

Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler

Aug 12, 2026🔧 No Patch
CVE-2026-18391
CVSS 9.8critical

WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection

Aug 12, 2026🔧 No Patch
CVE-2026-19089
CVSS 9.8critical

Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload

Aug 10, 2026🔧 No Patch
CVE-2026-15214
CVSS 4.3medium

Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR

Aug 7, 2026🔧 No Patch
CVE-2026-65559
CVSS 7.2high

WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Escalation vulnerability

Aug 6, 2026🔧 No Patch

Monitor WooCommerce in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

WooCommerce Security Vulnerabilities & Risk Score | 283 CVEs | SecAlerts - SecAlerts