Where
-Infinity
0

Vendor Risk Score

See how woocommerce compares to other vendors in security performance

View Risk Score →

Software

woocommerce
19
woocommerce automatewoo wordpress
7
woocommerce customers manager
7
woocommerce customer reviews for woocommerce
6
woocommerce social login
6
woocommerce wp erp
5
woocommerce product import export for woocommerce
4
woocommerce return refund and exchange for woocommerce
4
woocommerce shipping multiple addresses wordpress
4
woocommerce sms alert order notifications
4
woocommerce support ticket system
4
woocommerce woocommerce
4
woocommerce woocommerce wordpress
4
woocommerce active products tables for woocommerce
3
woocommerce designer pro
3
woocommerce openpos
3
woocommerce order export & order import for woocommerce
3
woocommerce orderconvo
3
woocommerce product filter
3
woocommerce returns and warranty requests wordpress
3
woocommerce stripe payment gateway wordpress
3
woocommerce wallet for woocommerce
3
woocommerce wallet system for woocommerce
3
woocommerce woocommerce stripe payment gateway
3
woocommerce box office wordpress
2
woocommerce compare products for woocommerce
2
woocommerce customer email verification
2
woocommerce drag and drop multiple file upload for woocommerce
2
woocommerce flexible refund and return order
2
woocommerce gift cards (gift vouchers and packages)
2
woocommerce payments plugin and checkout plugin
2
woocommerce paypal checkout payment gateway
2
woocommerce pdf invoices & packing slips for woocommerce
2
woocommerce pdf invoices, packing slips, delivery notes and shipping labels
2
woocommerce point of sale
2
woocommerce pre-orders
2
woocommerce print labels with barcodes
2
woocommerce product addons wordpress
2
woocommerce product input fields for woocommerce
2
woocommerce product table lite
2
woocommerce woocommerce pre-orders wordpress
2
woocommerce accounting for woocommerce
1
woocommerce add to cart custom redirect
1
woocommerce additional custom order status
1
woocommerce additional fees on checkout (free)
1
woocommerce additional order filters for woocommerce
1
woocommerce advance seat reservation management
1
woocommerce automatic order printing
1
woocommerce blocks – woolook
1
woocommerce booking & appointment plugin
1

WooCommerce Checkout Field Editor for WooCommerce (Pro)Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter

Risk 38
Severity
6.5
First published (updated )

WooCommerce Wallet for WooCommerceWallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action

Risk 22
Severity
4.3
First published (updated )

WooCommerce PDF Invoices & Packing Slips for WooCommercePDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute

Risk 22
Severity
4.3
First published (updated )

WooCommerce WordPressMemberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation

Risk 22
Severity
4.3
First published (updated )

WooCommerce Customer Reviews for WooCommerceCustomer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute

Risk 39
Severity
6.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WooCommerce WooCommerce Bulk Order UpdateBulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Read via 'csv_url' Parameter

Risk 27
Severity
5.3
First published (updated )

WooCommerce Wallet System for WooCommerceWordPress Wallet System for WooCommerce plugin <= 2.7.6 - Broken Access Control vulnerability

Risk 48
Severity
7.1
First published (updated )

WooCommerce WooCommerce Anti-FraudWordPress WooCommerce Anti-Fraud plugin <= 7.2.6 - Broken Access Control vulnerability

Risk 40
Severity
6.5
First published (updated )

WooCommerce WooCommerce Stripe Payment GatewayWooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter

Risk 40
Severity
6.5
First published (updated )

WooCommerce WooCommerce PayPal PaymentsWooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure

Risk 38
Severity
8.2
EPSS
0.40%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WooCommerce Woocommerce Category Banner ManagementWordPress Woocommerce Category Banner Management plugin <= 2.5.1 - PHP Object Injection vulnerability

Risk 79
Severity
8.8
First published (updated )

WooCommerce WordPress Fancy Product DesignerFancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Full Path Disclosure via 'pdf' Parameter

Risk 27
Severity
5.3
First published (updated )

WooCommerce PDF Catalog for WooCommercePDF Catalog for WooCommerce <= 1.1.18 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Risk 34
Severity
5.4
First published (updated )

WooCommerce Quick View for WooCommerceQuick View for WooCommerce <= 2.2.17 - Unauthenticated Private Product Disclosure

Risk 27
Severity
5.3
First published (updated )

WooCommerce Hide Category by User RoleHide Category by User Role for WooCommerce <= 2.3.1 - Missing Authorization to Unauthenticated Cache Flushing

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WooCommerce Customer Reviews CollectorCustomer Reviews Collector for WooCommerce <= 4.6.1 - Reflected Cross-Site Scripting

Risk 38
Severity
6.1
First published (updated )

WooCommerce Refund Request for WooCommerceRefund Request for WooCommerce <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Refund Status Update

Risk 22
Severity
4.3
First published (updated )

WooCommerce OrderConvoAdmin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated Information Disclosure

Risk 27
Severity
5.3
First published (updated )

WooCommerce OrderConvoAdmin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated User Impersonation in Order Messages

Risk 22
Severity
4.3
First published (updated )

WooCommerce Return Refund and Exchange For WooCommerceReturn Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WooCommerce Return Refund and Exchange For WooCommerceReturn Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Refund Request Cancellation

Risk 22
Severity
4.3
First published (updated )

WooCommerce WoocommerceLive sales notification for WooCommerce <= 2.3.39 - Missing Authorization to Unauthenticated Customer Data Exposure

Risk 43
Severity
7.5
First published (updated )

WooCommerce Checkout Files UploadCheckout Files Upload for WooCommerce <= 2.2.1 - Unauthenticated Stored Cross-Site Scripting

Risk 44
Severity
7.2
First published (updated )

WooCommerce Category and Product Woocommerce TabsCategory and Product Woocommerce Tabs <= 1.0 - Authenticated (Contributor+) Local File Inclusion

Risk 79
Severity
8.8
First published (updated )

WooCommerce Wishlist and Save for laterWishlist and Save for later for Woocommerce <= 1.1.22 - Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WooCommerce Products By Custom TaxWoocommerce – Products By Custom Tax <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Risk 39
Severity
6.4
First published (updated )

WooCommerce Flexible Refund and Return OrderFlexible Refund and Return Order for WooCommerce <= 1.0.42 - Incorrect Authorization to Authenticated (Contributor+) Refund Status Update

Risk 27
Severity
5.3
First published (updated )

WooCommerce Import Export For WooCommerceImport Export For WooCommerce <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update

Risk 22
Severity
4.3
First published (updated )

WooCommerce Designer ProWooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

Risk 49
Severity
8.6
First published (updated )

WooCommerce Simple Registration for WooCommerceSimple Registration for WooCommerce <= 1.5.8 - Cross-Site Request Forgery to Privilege Escalation via Role Request Approval

Risk 77
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203