CVE-2025-5062
- EPSS 0.42%
- Veröffentlicht 22.05.2025 03:42:08
- Zuletzt bearbeitet 30.09.2025 16:35:18
The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. Th...
CVE-2025-26762
- EPSS 0.04%
- Veröffentlicht 27.03.2025 15:52:22
- Zuletzt bearbeitet 27.03.2025 16:45:12
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce allows Stored XSS.This issue affects WooCommerce: from n/a through 9.7.0.
CVE-2024-10486
- EPSS 2.17%
- Veröffentlicht 18.11.2024 22:15:05
- Zuletzt bearbeitet 19.11.2024 21:57:32
The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attacke...
CVE-2024-39666
- EPSS 0.05%
- Veröffentlicht 18.08.2024 14:15:06
- Zuletzt bearbeitet 19.08.2024 12:59:59
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 9.1.2.
CVE-2024-35777
- EPSS 0.27%
- Veröffentlicht 09.07.2024 10:15:03
- Zuletzt bearbeitet 21.11.2024 09:20:52
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a through 8.9.2.
CVE-2024-1310
- EPSS 0.28%
- Veröffentlicht 15.04.2024 05:15:14
- Zuletzt bearbeitet 27.05.2025 16:13:32
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
CVE-2024-22155
- EPSS 0.23%
- Veröffentlicht 07.04.2024 18:15:08
- Zuletzt bearbeitet 21.11.2024 08:55:41
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2.
CVE-2023-47777
- EPSS 0.32%
- Veröffentlicht 30.11.2023 12:15:08
- Zuletzt bearbeitet 21.11.2024 08:30:47
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: ...
CVE-2017-17058
- EPSS 42.9%
- Veröffentlicht 29.11.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traver...