WPFactory develops a portfolio of WordPress and WooCommerce plugins focused on e-commerce functionality, including product management, VAT compliance, order processing, and customer verification features. The vendor's vulnerability profile concentrates on web-application input-handling and authorization issues, with recurring weaknesses in cross-site scripting, cross-site request forgery, and missing or bypassable authorization controls that are characteristic of server-side WordPress plugins. These weakness classes reflect the challenge of safely processing user input and managing admin capability checks within the WordPress plugin architecture. Defenders should treat this vendor's plugin updates as part of routine WordPress site hardening, particularly for shops handling sensitive customer and transaction data; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpfactory over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31276CRITICAL Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a | Jun 9, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-13528HIGH The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence | Feb 12, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-39601CRITICAL Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusion.This issue affects Custom CSS, JS & PHP: from n/a through | Apr 16, 2025 | 9.6 | 23 | NO | NO |
CVE-2025-69334MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Stored XSS | Jan 6, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-62096MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Maximum Products per User for WooCommerce maximum-products-per-user- | Dec 31, 2025 | 6.5 | 21 | NO | NO |
CVE-2024-43127HIGH Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPFactory Products, Order & Customers Export for WooCommerce allows Ref | Aug 12, 2024 | 7.1 | 21 | NO | NO |
CVE-2024-34370HIGH Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9. | May 17, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-56228HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce.This issue affect | Dec 31, 2024 | 7.1 | 20 | NO | NO |
CVE-2023-36689MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory WPFactory Helper plugin <= 1.5.2 versions. | Aug 5, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-0062MEDIUM The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode i | Feb 6, 2023 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpfactory.
Media articles that mention a CVE ID that affects a product developed by Wpfactory — matched by CVE ID, not by vendor name.