Ali2woo provides e-commerce integration and drop-shipping tools that connect AliExpress merchandise to WordPress-based online stores, exposing a small product surface centered on web-application input handling and authorization. The recurring vulnerability profile clusters around cross-site request forgery, cross-site scripting, missing authorization controls, and unrestricted file uploads—classic web-application vulnerabilities that reflect the complexity of mediating user-supplied content and administrative actions in commerce plugins. Current CVE counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ali2woo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2381HIGH The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_save_image function in al | Jun 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-37212HIGH Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a through 3.3.5. | Jun 21, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-4450MEDIUM The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ImportAjaxCont | Jun 19, 2024 | 6.3 | 19 | NO | NO |
CVE-2024-37211MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali2Woo Team Ali2Woo Lite allows Reflected XSS.This issue affects Ali2W | Jul 22, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ali2woo.
Media articles that mention a CVE ID that affects a product developed by Ali2woo — matched by CVE ID, not by vendor name.