CVE-2025-5062
- EPSS 0.42%
- Published 22.05.2025 03:42:08
- Last modified 30.09.2025 16:35:18
The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. Th...
CVE-2025-26762
- EPSS 0.04%
- Published 27.03.2025 15:52:22
- Last modified 27.03.2025 16:45:12
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce allows Stored XSS.This issue affects WooCommerce: from n/a through 9.7.0.
CVE-2024-10486
- EPSS 2.17%
- Published 18.11.2024 22:15:05
- Last modified 19.11.2024 21:57:32
The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attacke...
CVE-2024-39666
- EPSS 0.05%
- Published 18.08.2024 14:15:06
- Last modified 19.08.2024 12:59:59
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 9.1.2.
CVE-2024-35777
- EPSS 0.27%
- Published 09.07.2024 10:15:03
- Last modified 21.11.2024 09:20:52
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a through 8.9.2.
CVE-2024-1310
- EPSS 0.28%
- Published 15.04.2024 05:15:14
- Last modified 27.05.2025 16:13:32
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
CVE-2024-22155
- EPSS 0.23%
- Published 07.04.2024 18:15:08
- Last modified 21.11.2024 08:55:41
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2.
CVE-2023-47777
- EPSS 0.32%
- Published 30.11.2023 12:15:08
- Last modified 21.11.2024 08:30:47
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: ...
CVE-2017-17058
- EPSS 42.9%
- Published 29.11.2017 07:29:00
- Last modified 20.04.2025 01:37:25
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traver...