Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Booster

First CVE: Aug 12, 2019Active for: 7 yearsTotal CVEs: 39
31.3
VTI Score
Medium

Booster maintains a narrowly focused product line of e-commerce plugins for the WooCommerce platform, including variants positioned at different feature and pricing tiers. The vendor's vulnerability footprint concentrates on web application flaws endemic to e-commerce functionality: cross-site scripting, sensitive information exposure, unrestricted file uploads, and authorization bypass recur across its product range. The exposure reflects the attack surface inherent to plugins handling user input, file management, and payment-related operations in a shared WordPress ecosystem. A meaningful share of the vendor's disclosures reach serious severity, warranting attention from site operators managing WooCommerce storefronts. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
39
Total CVEs
More Total CVEs than 98% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Booster over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2019
6 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-34646CRITICAL
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a r
Aug 30, 20219.871NOYES
CVE-2026-56027CRITICAL
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
Jun 26, 20269.938NONO
CVE-2024-13342CRITICAL
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_order' function in all versions up
Aug 29, 20259.834NONO
CVE-2024-13744CRITICAL
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart fun
Apr 4, 20259.828NONO
CVE-2022-4017HIGH
The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, Booster Elite for WooCommerce WordPress plugin before 6.0.1 h
Jan 23, 20238.828NONO
CVE-2022-3763HIGH
The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 d
Nov 21, 20228.126NONO
CVE-2025-64196HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Reflected XSS.This
Nov 6, 20257.124NONO
CVE-2023-48747HIGH
Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster for WooComm
Jun 4, 20248.824NONO
CVE-2022-4016MEDIUM
The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 d
Dec 12, 20226.523NONO
CVE-2022-3762MEDIUM
The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 d
Nov 21, 20226.523NONO
View all 39 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products39 CVEs
72%
18%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network39 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (48.7%)
Unknown0 (0.0%)
Required20 (51.3%)
Privileges Required
Low18 (46.2%)
High1 (2.6%)
None20 (51.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Booster.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Booster — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Booster's Products

View all 4 CNAs →

Top CWEs