Medium 6.1
2026-05-01< 2.6.0
CVE-2024-13362
Minimum safe version
2.6.5
Update to 2.6.5 or later to address 7 fixable vulnerabilities
CVE-2024-13362
CVE-2026-27046
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress StoreCustomizer – WooCommerce plugin to Customize all WooCommerce Pages Plugin < 2.5.2 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress StoreCustomizer – WooCommerce plugin to Customize all WooCommerce Pages plugin < 2.3.8 - Sensitive Information Disclosure vulnerability
WordPress StoreCustomizer – WooCommerce plugin to Customize all WooCommerce Pages plugin < 2.3.8 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability