Woocommerce
Vendor:
First CVE: Jan 4, 2017 · Active for 9 years
16
Total CVEs
More Total CVEs than 93% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Woocommerce over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 4, 2017
9 years ago
Most Recent CVE
May 22, 2025
432 days ago
CVE Severity & Scoring
Woocommerce16 CVEs
75%
25%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (31.3%)
Unknown0 (0.0%)
Required11 (68.8%)
Privileges Required
Low4 (25.0%)
High5 (31.3%)
None7 (43.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18356HIGH In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager pr | Jan 15, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-20891HIGH WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS) via includes/admin | Jun 19, 2020 | 8.8 | 27 | NO | NO |
CVE-2018-20714HIGH The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which le | Jan 15, 2019 | 8.1 | 25 | NO | NO |
CVE-2023-52222HIGH Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2. | Jan 8, 2024 | 8.8 | 24 | NO | NO |
CVE-2020-29156MEDIUM The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action. | Dec 27, 2020 | 5.3 | 20 | NO | NO |
CVE-2024-9944MEDIUM The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements | Oct 15, 2024 | 6.1 | 19 | NO | NO |
CVE-2022-2099MEDIUM The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles | Jul 17, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-32790MEDIUM Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and | Jul 26, 2021 | 4.9 | 19 | NO | NO |
CVE-2025-5062MEDIUM The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insuf | May 22, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-37297MEDIUM WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a li | Jun 12, 2024 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Woocommerce
Top CWEs
Versions
No cataloged versions.