Woocommerce
Woocommerce: vulnerabilidades y CVE
Woocommerce tiene 20 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-50972 | Crítica (9.3) | 1.1% | — | 20 jun 2026 | WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the… |
| CVE-2026-3589 | Alta (7.5) | 0.18% | — | 6 mar 2026 | The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create… |
| CVE-2025-15033 | Media (6.5) | 0.33% | — | 22 dic 2025 | A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the… |
| CVE-2023-7320 | Media (5.3) | 0.33% | — | 29 oct 2025 | The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external… |
| CVE-2025-5062 | Media (6.1) | 0.44% | — | 22 may 2025 | The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output… |
| CVE-2024-9944 | Media (6.1) | 0.59% | — | 15 oct 2024 | The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes… |
| CVE-2024-37297 | Media (5.4) | 0.48% | — | 12 jun 2024 | WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML &… |
| CVE-2022-0775 | Media (4.3) | 0.68% | — | 16 ene 2024 | The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment |
| CVE-2023-52222 | Alta (8.8) | 0.29% | — | 8 ene 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2. |
| CVE-2023-32575 | Media (4.8) | 0.40% | — | 25 ago 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin <= 1.3.25 versions. |
| CVE-2022-2099 | Media (4.8) | 0.65% | — | 17 jul 2022 | The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles |
| CVE-2021-32790 | Media (4.9) | 1.3% | — | 26 jul 2021 | Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already)… |
| CVE-2021-24323 | Media (4.8) | 0.74% | — | 17 may 2021 | When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when… |
| CVE-2020-29156 | Media (5.3) | 4.0% | — | 27 dic 2020 | The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action. |
| CVE-2019-20891 | Alta (8.8) | 0.53% | — | 19 jun 2020 | WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS) via… |
| CVE-2019-9168 | Media (6.1) | 0.98% | — | 26 feb 2019 | WooCommerce before 3.5.5 allows XSS via a Photoswipe caption. |
| CVE-2018-20714 | Alta (8.1) | 1.8% | — | 15 ene 2019 | The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not… |
| CVE-2017-18356 | Alta (8.8) | 2.0% | — | 15 ene 2019 | In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs… |
| CVE-2015-2329 | Media (6.1) | 1.2% | — | 8 feb 2018 | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order. |
| CVE-2016-10112 | Media (4.8) | 0.90% | — | 4 ene 2017 | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.