Woo develops a narrowly scoped e-commerce product platform, with its disclosed vulnerabilities centered on web-application input handling and authorization controls typical of merchant-facing commerce systems. The recurring weakness classes—SQL injection, cross-site scripting, and missing authorization—reflect the data-handling and access-control demands of a payment and customer-management platform; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Woo over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-35879CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Ve | Oct 31, 2023 | 9.8 | 29 | NO | NO |
CVE-2017-20193MEDIUM The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input saniti | Oct 16, 2024 | 6.1 | 21 | NO | NO |
CVE-2023-33331HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Ve | Dec 18, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-36512MEDIUM Missing Authorization vulnerability in Woo AutomateWoo.This issue affects AutomateWoo: from n/a through 5.7.5. | Jun 19, 2024 | 6.5 | 18 | NO | NO |
CVE-2023-52186MEDIUM Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.2. | Jun 11, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Woo.
Media articles that mention a CVE ID that affects a product developed by Woo — matched by CVE ID, not by vendor name.