WooCommerce < 10.5.3 - Cross-Site Request Forgery
WooCommerce
Minimum safe version
10.5.3
Update to 10.5.3 or later to address 94 fixable vulnerabilities
CVE-2025-15033
CVE-2025-49042
WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting
CVE-2025-26762
WordPress WooCommerce Plugin < 9.4.3 is vulnerable to Broken Access Control
CVE-2024-9944
CVE-2024-39666
WooCommerce < 8.4.0 - Reflected Cross-Site Scripting
CVE-2024-35777
CVE-2024-37297
WordPress WooCommerce Plugin <= 8.9.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-1310
WordPress WooCommerce Plugin <= 8.3.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-22155
WooCommerce < 8.4.0 - Reflected Cross-Site Scripting
CVE-2023-52222
WooCommerce < 7.9.0 - Sensitive Information Exposure
WooCommerce < 7.0.1 - Authenticated(Shop Manager+) Sensitive Information Exposure
CVE-2023-47777
WooCommerce < 7.9 - Unauthenticated Sensitive Information Disclosure
WooCommerce < 7.0.1 - Shop Manager+ User Metadata Disclosure
WooCommerce <= 7.8.2 - Sensitive Information Exposure
WooCommerce <= 7.0.0 - Authenticated(Shop Manager+) Sensitive Information Exposure
WooCommerce <= 2.6.2 - Authenticated Cross-Site Scripting (XSS)
WooCommerce 2.0.20-2.3.10 - Object Injection / XXE
WooCommerce <= 2.4.8 - Authenticated Cross-Site Scripting (XSS)
WooCommerce <= 2.6.3 - Stored Cross Site Scripting (XSS) via REST API
WooCommerce <= 3.4.4 - Potential Object Injection
WooCommerce <= 3.4.5 - Authenticated Object Injection
WooCommerce <= 3.4.5 - Authenticated Stored XSS
WooCommerce <= 3.4.5 - Authenticated Phar Deserialization
WooCommerce <= 3.5.0 - Authenticated Stored XSS
WooCommerce <= 3.6.4 - Cross-Site Request Forgery (CSRF) & File Type Check
WooCommerce < 4.1.0 - Unescaped Metadata when Duplicating Products
WooCommerce < 4.2.1 - Potential Cross-Site Scripting (XSS) via SelectWoo
WooCommerce < 4.6.2 - Guest Account Creation
WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Analytics Report Leaks
CVE-2022-0775
WooCommerce < 6.2.1 - Path Traversal via Importers
WooCommerce < 6.3.1 - Orders Marked as Paid (via PayPal Standard Gateway)
WooCommerce 2.0.17 - hide-wc-extensions-message Parameter Reflected XSS
WooCommerce 2.0.12 - index.php calc_shipping_state Parameter XSS
WooCommerce <= 2.1.12 - Reflected Cross-Site Scripting (XSS)
WooCommerce <= 2.0.12 - Self-Reflected Cross-Site Scripting
WooCommerce <= 2.0.17 - Cross-Site Scripting
WooCommerce <= 2.2.2 - Reflected Cross-Site Scripting
WooCommerce <= 2.3.10 - PHP Object Injection
WooCommerce < 2.4.9 - Cross-site Scripting
WooCommerce <= 2.6.2 - Stored Cross-Site Scripting
WooCommerce <= 2.6.3 - Stored Cross-Site Scripting via REST-API
WooCommerce <= 3.4.4 - Authenticated PHP Object Injection
WooCommerce <= 3.5.1 - Authenticated Stored Cross-Site Scripting
WooCommerce <= 3.6.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WooCommerce <= 3.6.4 - Missing File Type Validation
WooCommerce <= 4.0.4 - Unauthorized Post Meta Creation/Modification
WooCommerce <= 4.2.0 - Reflected Cross-Site Scripting
WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation
WooCommerce <= 6.2.0 - Path Traversal via Tax Importer
WooCommerce <= 6.2.0 - Incorrect Authorization Checks on REST API Endpoints
WooCommerce < 6.3.1 - Unauthorized Order Status Change
WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Information Disclosure
CVE-2022-2099
WordPress WooCommerce Plugin <= 2.3.5 - SQL Injection
WordPress WooCommerce Plugin <= 2.0.12 - Cross Site Scripting
WordPress WooCommerce Plugin <= 2.0.17 - Reflected Cross Site Scripting
WordPress WooCommerce Plugin <= 2.1.12 - Reflected XSS
WordPress WooCommerce Plugin <= 2.3.10 - XXE
WordPress WooCommerce Plugin <= 2.4.8 - Cross Site Scripting
WordPress WooCommerce Plugin <= 2.6.2 - Cross Site Scripting
WordPress WooCommerce Plugin <= 2.6.3 - Cross Site Scripting
WordPress WooCommerce plugin <=3.2.3 - Authenticated PHP Object Injection vulnerability
WordPress WooCommerce plugin <= 3.4.4 - Potential Object Injection vulnerability
WordPress WooCommerce plugin <= 3.4.5 - Authenticated Object Injection vulnerability
WordPress WooCommerce plugin <= 3.4.5 - Authenticated File Deletion to Privilege Escalation vulnerability
WordPress WooCommerce plugin <= 3.4.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress WooCommerce plugin <= 3.5.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2019-9168
WordPress WooCommerce plugin <= 3.6.4 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress WooCommerce plugin <= 4.6.1 - Guest Account Creation vulnerability
WordPress WooCommerce plugin <= 5.1.0 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
WordPress WooCommerce plugin <= 5.5.0 - Unauthenticated SQL Injection (SQLi) vulnerability
WordPress WooCommerce plugin <= 5.6.0 - Analytics Report Leaks vulnerability
WordPress WooCommerce plugin <= 6.2.0 - Arbitrary Comment Deletion vulnerability
WordPress WooCommerce plugin <= 6.2.0 - Path Traversal via Importers vulnerability
WordPress WooCommerce plugin <= 6.3.0 - Orders Status Change (via PayPal Standard Gateway) vulnerability
CVE-2014-6313
CVE-2015-2069
CVE-2016-10112
CVE-2017-17058
CVE-2015-2329
CVE-2018-20714
CVE-2017-18356
CVE-2020-29156
CVE-2021-24323
CVE-2021-32790