CVE-2026-32586
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
Minimum safe version
7.11.3
Update to 7.11.3 or later to address 46 fixable vulnerabilities
CVE-2025-64379
CVE-2025-64380
CVE-2025-64196
CVE-2024-13342
CVE-2024-13708
CVE-2024-13744
CVE-2024-12278
CVE-2024-9170
CVE-2024-9239
CVE-2024-3957
CVE-2024-29760
CVE-2024-1534
CVE-2024-1986
CVE-2024-1054
CVE-2023-48747
CVE-2023-48333
CVE-2023-5638
CVE-2023-40002
Booster for WooCommerce <= 7.1.1 - Authenticated (Subscriber+) Information Disclosure via Shortcode
Booster for WooCommerce < 7.1.0 - Shop Manager+ Missing Authorization to Arbitrary Options Update
CVE-2023-4945
CVE-2023-4796
Booster for WooCommerce < 5.6.2 - Reflected Cross-Site Scripting
Booster for WooCommerce (Free < 5.6.3, Premium < 5.6.1) - Subscriber+ Order Status Update
CVE-2022-4017
Booster for WooCommerce 7.0.0 - Authenticated (Shop Manager+) Missing Authorization to Arbitrary Options Update
WordPress Booster for WooCommerce Plugin <= 7.0.0 is vulnerable to Broken Access Control
Booster for WooCommerce <= 5.5.8 - Reflected Cross-Site Scripting
Booster for WooCommerce <= 5.5.9 - Reflected Cross-Site Scripting
Booster for WooCommerce <= 5.6.1 - Cross-Site Request Forgery
Booster for WooCommerce (Free <= 5.6.2 and Premium <= 5.6.0) - Authenticated (Subscriber+) Order Modification
Booster for WooCommerce <= 5.6.8 - Cross-Site Request Forgery
CVE-2022-4227
WordPress Booster for WooCommerce Plugin <= 5.6.6 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2022-3762
CVE-2022-3763
CVE-2022-41805
WordPress Booster for WooCommerce plugin <= 5.6.2 - Authenticated Order Status Update vulnerability
WordPress Booster Plus for WooCommerce premium plugin <= 5.6.0 - Authenticated Order Status Update vulnerability
WordPress Booster for WooCommerce plugin <= 5.5.9 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2018-20966
CVE-2021-34646
CVE-2021-25001
CVE-2021-25000
CVE-2021-24999