WooCommerce
woocommerce · plugin
Known security vulnerabilities for WooCommerce. Find out in seconds which version runs on your site with WP Lens.
15 known vulnerabilities
1 critical · 6 exploitable without logging in · latest Sep 8, 2026
Listed on wordpress.org · latest 11.1.2 · last updated Sep 22, 2026 · 7M+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.3
CVE-2022-50972unauthenticated
WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
- High 8.8
CVE-2023-52222unauthenticated · needs a click≤ 8.2.2
WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF)
- High 7.6
CVE-2026-57777high privilege→ 11.0
WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability
- High 7.5
CVE-2026-48888unauthenticated→ 11.1.0
WordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerability
- Medium 6.1
CVE-2024-9944unauthenticated≤ 9.0.2
WooCommerce <= 9.0.2 - Unauthenticated HTML Injection
- Medium 5.9
CVE-2025-49042high privilege≤ 10.0.2
WordPress WooCommerce plugin <= 10.0.2 - Cross Site Scripting (XSS) vulnerability
- Medium 5.9
CVE-2025-26762high privilege≤ 9.7.0
WordPress WooCommerce plugin <= 9.7.0 - Cross Site Scripting (XSS) vulnerability
- Medium 5.9
CVE-2024-39666high privilege≤ 9.1.2
WordPress WooCommerce plugin <= 9.1.2 - Cross Site Scripting (XSS) vulnerability
- Medium 5.4
CVE-2023-47777login required≤ 8.1.1
WordPress WooCommerce and WooCommerce Blocks plugins - Auth. Cross-Site Scripting (XSS) vulnerability
- Medium 5.3
CVE-2023-7320unauthenticated≤ 7.8.2
WooCommerce <= 7.8.2 - Sensitive Information Exposure
- Medium 4.8
CVE-2016-10112high privilege
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to
- Medium 4.3
CVE-2024-22155unauthenticated · needs a click≤ 8.5.2
WordPress WooCommerce plugin <= 8.5.2 - Cross Site Request Forgery (CSRF) vulnerability
- Medium 4.3
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary w
- Medium 4.3
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary we
- Low 3.5
CVE-2024-35777high privilege≤ 8.9.2
WordPress WooCommerce plugin <= 8.9.2 - Content Injection vulnerability
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).