SecAlerts
WooCommerce logo

WooCommerce

Security Risk Profile

45
/100
medium

Security Risk Score

Comprehensive risk assessment based on 278 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 4, 2017 to present

278
Total CVEs
120
Critical+High
2
Exploited
83
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
83
Critical/High
Risk Level
45/100
medium
⚠️ 2 Active Exploits🆕 3Fresh (<7d)📈 10 in Last 30 Days

Severity Distribution

Critical
25
High
95
Medium
156
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
37

Age Distribution

Common Weaknesses (CWE)

1
XSS
72
2
CSRF
32
3
Path Traversal
17
4
SQL Injection
15
5
Malicious File Upload
14

Most Affected Products

1. WooCommerce WooCommerce WordPress40
2. weDevs Wp Erp Wordpress7
3. WooCommerce Customers Manager7
4. Vanquish Woocommerce Customers Manager Wordpress7
5. WooCommerce Automatewoo Wordpress7

Recent Vulnerabilities

See more →
CVE-2026-16621
CVSS 5.3medium

Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler

8/12/2026🔧 No Patch
CVE-2026-18391
CVSS 9.8critical

WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection

8/12/2026🔧 No Patch
CVE-2026-19089
CVSS 9.8critical

Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload

8/10/2026🔧 No Patch
CVE-2026-15214
CVSS 4.3medium

Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR

8/7/2026🔧 No Patch
CVE-2026-65559
CVSS 7.2high

WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Escalation vulnerability

8/6/2026🔧 No Patch
CVE-2025-14073
CVSS 5.3medium

WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information Disclosure

8/1/2026🔧 No Patch
CVE-2026-15397
CVSS 7.2high

Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation via wps_sfw_install_plugin_configuration AJAX Action

7/30/2026🔧 No Patch
CVE-2026-11782
CVSS 5.9medium

Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR

7/30/2026🔧 No Patch
CVE-2026-12144
CVSS 8.8high

Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter

7/29/2026🔧 No Patch
CVE-2026-14955
CVSS 6.5medium

Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter

7/25/2026🔧 No Patch

Monitor WooCommerce in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.