SecAlerts
WooCommerce logo

WooCommerce

Security Risk Profile

38
/100
low

Security Risk Score

Comprehensive risk assessment based on 269 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 4, 2017 to present

269
Total CVEs
115
Critical+High
2
Exploited
78
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
78
Critical/High
Risk Level
38/100
low
⚠️ 2 Active Exploits🆕 1Fresh (<7d)📈 7 in Last 30 Days

Severity Distribution

Critical
23
High
92
Medium
152
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
37

Age Distribution

Common Weaknesses (CWE)

1
XSS
72
2
CSRF
32
3
Path Traversal
17
4
SQL Injection
15
5
Malicious File Upload
12

Most Affected Products

1. WooCommerce WooCommerce WordPress40
2. weDevs Wp Erp Wordpress7
3. WooCommerce Customers Manager7
4. Vanquish Woocommerce Customers Manager Wordpress7
5. WooCommerce Automatewoo Wordpress7

Recent Vulnerabilities

See more →
CVE-2026-14955
CVSS 6.5medium

Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter

7/25/2026🔧 No Patch
CVE-2026-12103
CVSS 4.3medium

Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action

7/11/2026🔧 No Patch
CVE-2026-13116
CVSS 4.3medium

PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute

7/11/2026🔧 No Patch
CVE-2026-11359
CVSS 4.3medium

Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation

7/9/2026🔧 No Patch
CVE-2026-13771
CVSS 6.4medium

Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute

7/9/2026🔧 No Patch
CVE-2026-14500
CVSS 5.3medium

Bulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Read via 'csv_url' Parameter

7/8/2026🔧 No Patch
CVE-2026-57332
CVSS 7.1high

WordPress Wallet System for WooCommerce plugin <= 2.7.6 - Broken Access Control vulnerability

6/29/2026🔧 No Patch
CVE-2026-49072
CVSS 6.5medium

WordPress WooCommerce Anti-Fraud plugin <= 7.2.6 - Broken Access Control vulnerability

6/17/2026🔧 No Patch
CVE-2026-2381
CVSS 6.5medium

WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter

6/16/2026🔧 No Patch
CVE-2026-9284
CVSS 8.2EPSS 0%high

WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure

5/23/2026🔧 No Patch

Monitor WooCommerce in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

WooCommerce Security Vulnerabilities & Risk Score | 269 CVEs | SecAlerts - SecAlerts