VYPR

Vendor CVEs

WooCommerce

All CVEs

75 total · sorted by risk
  • CVE-2023-35880MedJul 17, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions.

  • CVE-2023-33316MedMay 28, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions.

  • CVE-2020-29156MedDec 27, 2020
    risk 0.35cvss 5.3epss 0.04

    The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

  • CVE-2019-14979MedAug 29, 2019
    risk 0.35cvss 5.3epss 0.01

    cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states…

  • CVE-2019-14978MedAug 29, 2019
    risk 0.35cvss 5.3epss 0.01

    /payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for lower than the intended price.

  • CVE-2023-51496MedJun 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

  • CVE-2023-51494MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1.

  • CVE-2025-5062MedMay 22, 2025
    risk 0.33cvss 6.1epss 0.00

    The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. This makes it possible for…

  • CVE-2021-32790MedJul 26, 2021
    risk 0.32cvss 4.9epss 0.01

    Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can…

  • CVE-2017-20193MedOct 16, 2024
    risk 0.31cvss 4.7epss 0.00

    The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2016-10112MedJan 4, 2017
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.

  • CVE-2024-9944MedOct 15, 2024
    risk 0.28cvss 5.3epss 0.01

    The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject…

  • CVE-2024-37297MedJun 12, 2024
    risk 0.28cvss 5.4epss 0.00

    WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While the content is not saved to the database,…

  • CVE-2023-52222MedJan 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.

  • CVE-2023-36511MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Order Barcodes plugin <= 1.6.4 versions.

  • CVE-2023-35917MedJun 22, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.

  • CVE-2022-2099MedJul 17, 2022
    risk 0.24cvss 4.8epss 0.01

    The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

  • CVE-2021-24323MedMay 17, 2021
    risk 0.24cvss 4.8epss 0.01

    When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

  • CVE-2022-0775MedJan 16, 2024
    risk 0.21cvss 4.3epss 0.01

    The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment

  • CVE-2015-10115MedJun 5, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affects the function process_request of the file classes/class-woosidebars-sbm-converter.php. The manipulation leads to open redirect.…

  • CVE-2015-10114MedJun 5, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the function enable_custom_post_sidebars of the file classes/class-woo-sidebars.php. The manipulation of the argument sendback leads to…

  • CVE-2015-10112MedJun 5, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url leads to open redirect. It is possible to…

  • CVE-2015-10113LowJun 5, 2023
    risk 0.16cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the function admin_screen_logic of the file wooframework-tweaks.php. The manipulation of the argument url leads to open redirect. The…

  • CVE-2015-10104LowApr 30, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipulation of the argument redirect_url leads…

  • CVE-2018-20782HigFeb 17, 2019
    risk 0.04cvss 7.5epss 0.10

    The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.

Page 2 of 2