Automattic

Woocommerce

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 08.09.2026 07:25:20
  • Zuletzt bearbeitet 08.09.2026 13:12:58

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

  • EPSS 0.24%
  • Veröffentlicht 04.09.2026 08:12:00
  • Zuletzt bearbeitet 04.09.2026 17:16:57

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from n/a before 11.0.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 06.03.2026 09:11:10
  • Zuletzt bearbeitet 15.04.2026 14:42:29

The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF at...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 22.12.2025 18:57:39
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions throu...

  • EPSS 0.31%
  • Veröffentlicht 29.10.2025 06:45:48
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can al...

  • EPSS 0.17%
  • Veröffentlicht 29.10.2025 04:50:12
  • Zuletzt bearbeitet 23.04.2026 15:31:13

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through <= 10.0.2.

  • EPSS 0.42%
  • Veröffentlicht 22.05.2025 03:42:08
  • Zuletzt bearbeitet 30.09.2025 16:35:18

The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. Th...

  • EPSS 0.2%
  • Veröffentlicht 27.03.2025 15:52:22
  • Zuletzt bearbeitet 23.04.2026 15:25:56

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through <= 9.7.0.

  • EPSS 0.88%
  • Veröffentlicht 18.11.2024 22:15:05
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attacke...

  • EPSS 0.4%
  • Veröffentlicht 18.08.2024 14:15:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 9.1.2.