Booster maintains a narrowly focused product line of e-commerce plugins for the WooCommerce platform, including variants positioned at different feature and pricing tiers. The vendor's vulnerability footprint concentrates on web application flaws endemic to e-commerce functionality: cross-site scripting, sensitive information exposure, unrestricted file uploads, and authorization bypass recur across its product range. The exposure reflects the attack surface inherent to plugins handling user input, file management, and payment-related operations in a shared WordPress ecosystem. A meaningful share of the vendor's disclosures reach serious severity, warranting attention from site operators managing WooCommerce storefronts. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Booster over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34646CRITICAL Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a r | Aug 30, 2021 | 9.8 | 71 | NO | YES |
CVE-2026-56027CRITICAL Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. | Jun 26, 2026 | 9.9 | 38 | NO | NO |
CVE-2024-13342CRITICAL The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_order' function in all versions up | Aug 29, 2025 | 9.8 | 34 | NO | NO |
CVE-2024-13744CRITICAL The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart fun | Apr 4, 2025 | 9.8 | 28 | NO | NO |
CVE-2022-4017HIGH The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, Booster Elite for WooCommerce WordPress plugin before 6.0.1 h | Jan 23, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-3763HIGH The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 d | Nov 21, 2022 | 8.1 | 26 | NO | NO |
CVE-2025-64196HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Reflected XSS.This | Nov 6, 2025 | 7.1 | 24 | NO | NO |
CVE-2023-48747HIGH Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster for WooComm | Jun 4, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-4016MEDIUM The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 d | Dec 12, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-3762MEDIUM The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 d | Nov 21, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Booster.
Media articles that mention a CVE ID that affects a product developed by Booster — matched by CVE ID, not by vendor name.