Xforwoocommerce develops a modestly scoped suite of WooCommerce plugins for e-commerce sites, spanning functionality from SEO automation and spam control to product customization and cart management. The durable signal in its vulnerability profile centers on authorization-boundary weaknesses across these plugins, reflecting the access-control demands inherent to multi-role commerce platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xforwoocommerce over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4337HIGH Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various ve | Jun 7, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-33628HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows PHP Local File Inclusion.This issue affects XforWooCommerce: | Jun 4, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xforwoocommerce.
Media articles that mention a CVE ID that affects a product developed by Xforwoocommerce — matched by CVE ID, not by vendor name.