Woocommerce is a widely deployed e-commerce platform and plugin ecosystem built on WordPress that powers online storefronts ranging from small merchants to large retailers, making it a prominent fixture in the web-commerce attack surface. Its vulnerability footprint concentrates in the core platform and complementary plugins such as AutomateWoo, Shipping Multiple Addresses, and Pre-Orders, spanning a modestly represented but well-distributed set of disclosures. The recurring weakness classes—cross-site scripting, cross-site request forgery, missing authorization, open redirects, and authorization-bypass flaws—reflect the authentication, state-management, and input-handling demands of a multi-tenant e-commerce plugin architecture where user-supplied data flows through payment processing, account management, and administrative interfaces. Defenders should prioritize keeping the core platform and widely used extensions current, as even modestly severity-graded flaws in this context can compromise merchant and customer data. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Woocommerce over time
Signals from CVEs in this vendor scope (70 CVEs).
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24212CRITICAL The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site whi | Apr 5, 2021 | 9.8 | 42 | NO | YES |
CVE-2021-24940MEDIUM The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Refle | Mar 14, 2022 | 6.1 | 31 | NO | YES |
CVE-2023-35879CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Ve | Oct 31, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-35049CRITICAL Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0. | Jun 19, 2024 | 9.8 | 28 | NO | NO |
CVE-2019-7441MEDIUM cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demo | Mar 21, 2019 | 6.5 | 28 | NO | YES |
CVE-2017-18356HIGH In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager pr | Jan 15, 2019 | 8.8 | 28 | NO | NO |
CVE-2023-51494CRITICAL Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1. | Jun 9, 2024 | 9.8 | 27 | NO | NO |
CVE-2020-35627HIGH Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the func | Dec 28, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-20891HIGH WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS) via includes/admin | Jun 19, 2020 | 8.8 | 27 | NO | NO |
CVE-2023-36513HIGH Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions. | Jul 17, 2023 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (70 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Woocommerce.
Media articles that mention a CVE ID that affects a product developed by Woocommerce — matched by CVE ID, not by vendor name.