Automattic

Woocommerce

9 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Published 22.05.2025 03:42:08
  • Last modified 30.09.2025 16:35:18

The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. Th...

  • EPSS 0.04%
  • Published 27.03.2025 15:52:22
  • Last modified 27.03.2025 16:45:12

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce allows Stored XSS.This issue affects WooCommerce: from n/a through 9.7.0.

  • EPSS 2.17%
  • Published 18.11.2024 22:15:05
  • Last modified 19.11.2024 21:57:32

The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attacke...

  • EPSS 0.05%
  • Published 18.08.2024 14:15:06
  • Last modified 19.08.2024 12:59:59

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 9.1.2.

  • EPSS 0.27%
  • Published 09.07.2024 10:15:03
  • Last modified 21.11.2024 09:20:52

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a through 8.9.2.

Exploit
  • EPSS 0.28%
  • Published 15.04.2024 05:15:14
  • Last modified 27.05.2025 16:13:32

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

  • EPSS 0.23%
  • Published 07.04.2024 18:15:08
  • Last modified 21.11.2024 08:55:41

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2.

Exploit
  • EPSS 0.32%
  • Published 30.11.2023 12:15:08
  • Last modified 21.11.2024 08:30:47

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: ...

  • EPSS 42.9%
  • Published 29.11.2017 07:29:00
  • Last modified 20.04.2025 01:37:25

The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traver...