Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Woocommerce

First CVE: Jan 4, 2017Active for: 10 yearsTotal CVEs: 70
23.4
VTI Score
Low

Woocommerce is a widely deployed e-commerce platform and plugin ecosystem built on WordPress that powers online storefronts ranging from small merchants to large retailers, making it a prominent fixture in the web-commerce attack surface. Its vulnerability footprint concentrates in the core platform and complementary plugins such as AutomateWoo, Shipping Multiple Addresses, and Pre-Orders, spanning a modestly represented but well-distributed set of disclosures. The recurring weakness classes—cross-site scripting, cross-site request forgery, missing authorization, open redirects, and authorization-bypass flaws—reflect the authentication, state-management, and input-handling demands of a multi-tenant e-commerce plugin architecture where user-supplied data flows through payment processing, account management, and administrative interfaces. Defenders should prioritize keeping the core platform and widely used extensions current, as even modestly severity-graded flaws in this context can compromise merchant and customer data. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
70
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Woocommerce over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 4, 2017
9 years ago
Most Recent CVE
May 22, 2025
428 days ago

Products(32 total)

Top CVEs

Signals from CVEs in this vendor scope (70 CVEs).

70 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24212CRITICAL
The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site whi
Apr 5, 20219.842NOYES
CVE-2021-24940MEDIUM
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Refle
Mar 14, 20226.131NOYES
CVE-2023-35879CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Ve
Oct 31, 20239.829NONO
CVE-2023-35049CRITICAL
Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.
Jun 19, 20249.828NONO
CVE-2019-7441MEDIUM
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demo
Mar 21, 20196.528NOYES
CVE-2017-18356HIGH
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager pr
Jan 15, 20198.828NONO
CVE-2023-51494CRITICAL
Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1.
Jun 9, 20249.827NONO
CVE-2020-35627HIGH
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the func
Dec 28, 20208.827NONO
CVE-2019-20891HIGH
WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS) via includes/admin
Jun 19, 20208.827NONO
CVE-2023-36513HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions.
Jul 17, 20238.825NONO
View all 70 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products70 CVEs
63%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network70 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low70 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (35.7%)
Unknown0 (0.0%)
Required45 (64.3%)
Privileges Required
Low13 (18.6%)
High8 (11.4%)
None49 (70.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (70 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
2.9% of CVEs· 95th percentile
ExploitDB
1 CVE
1.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Woocommerce.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Woocommerce — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Woocommerce's Products

View all 6 CNAs →

Top CWEs