WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro WooCommerce?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress WooCommerce — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: woocommerce
  • 7000000+ instalaciones activas

ecommerceonline storesell onlineshopshopping cart

Estado de mantenimiento

  • Última versión conocida: 10.9.4
  • Requiere PHP: 7.4+

Vulnerabilidades conocidas

26 CVEs conocidos registrados para WooCommerce.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2022-50972 WooCommerce [woocommerce] == 7.1.0 (unfixed) Crítica 9,8 < 7.1.0 7.1.0 2026-06-20 ✓ corregido en la última versión
CVE-2025-15033 WooCommerce [woocommerce] < 10.4.3 Exposición de información sensible a un actor no autorizado Media 6,5 < 10.4.3 10.4.3 2025-12-22 ✓ corregido en la última versión
CVE-2025-49042 WooCommerce [woocommerce] < 10.0.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 10.0.3 10.0.3 2025-10-29 ✓ corregido en la última versión
CVE-2025-26762 WooCommerce [woocommerce] < 9.7.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,9 < 9.7.1 9.7.1 2025-03-12 ✓ corregido en la última versión
WooCommerce [woocommerce] < 9.4.3 Desconocido < 9.4.3 9.4.3 2024-12-04 ✓ corregido en la última versión
CVE-2024-9944 WooCommerce [woocommerce] < 9.1.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 9.1.0 9.1.0 2024-10-14 ✓ corregido en la última versión
CVE-2024-39666 WooCommerce [woocommerce] < 9.1.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,9 < 9.1.3 9.1.3 2024-08-16 ✓ corregido en la última versión
CVE-2024-35777 WooCommerce [woocommerce] < 9.0.0 Neutralización incorrecta de elementos especiales en la salida usada por un componente posterior (inyección) Baja 3,5 < 9.0.0 9.0.0 2024-06-27 ✓ corregido en la última versión

CVE-2022-50972

WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-15033

A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it has been fixed in 8.1.3. It does not affect WooCommerce 8.0 or earlier.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-49042

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-26762

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 9.4.3

<p>WordPress WooCommerce Plugin < 9.4.3 is vulnerable to Broken Access Control</p><p>Software: WooCommerce</p><p>Fixed in version 9.4.3 </p><p>Affected Version < 9.4.3</p>

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-9944

The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-39666

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-35777

The WooCommerce plugin for WordPress is vulnerable to content injection in all versions up to, and including, 8.9.2. This is due to the plugin not properly restricting/validating content. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inject arbitrary content.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 89 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
WooCommerce [woocommerce] < 8.9.3 Desconocido < 8.9.3 8.9.3 2024-06-11 ✓ corregido en la última versión
CVE-2024-37297 WooCommerce [woocommerce] < 8.9.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 8.9.3 8.9.3 2024-06-10 ✓ corregido en la última versión
CVE-2024-22155 WooCommerce [woocommerce] < 8.6.0 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 8.6.0 8.6.0 2024-04-05 ✓ corregido en la última versión
CVE-2024-1310 WooCommerce [woocommerce] < 8.6 Control de acceso incorrecto Media 4,9 < 8.6 8.6 2024-03-25 ✓ corregido en la última versión
CVE-2022-0775 WooCommerce [woocommerce] < 6.2.1 Autorización incorrecta Media 4,3 < 6.2.1 6.2.1 2024-01-16 ✓ corregido en la última versión
WooCommerce [woocommerce] < 8.4.0 Desconocido < 8.4.0 8.4.0 2024-01-12 ✓ corregido en la última versión
CVE-2023-52222 WooCommerce [woocommerce] < 8.3.0 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 8.3.0 8.3.0 2024-01-05 ✓ corregido en la última versión
CVE-2023-47777 WooCommerce [woocommerce] < 8.2.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 8.2.0 8.2.0 2023-11-15 ✓ corregido en la última versión
WooCommerce [woocommerce] < 7.0.1 Desconocido < 7.0.1 7.0.1 2023-09-11 ✓ corregido en la última versión
WooCommerce [woocommerce] < 7.9.0 Desconocido < 7.9.0 7.9.0 2023-09-11 ✓ corregido en la última versión
CVE-2022-2099 WooCommerce [woocommerce] < 6.6.0 Codificación o escapado incorrecto de la salida Media 4,8 < 6.6.0 6.6.0 2022-06-20 ✓ corregido en la última versión
WooCommerce [woocommerce] < 5.7.0 Desconocido < 5.7.0 5.7.0 2022-04-10 ✓ corregido en la última versión
WooCommerce [woocommerce] < 6.3.1 Desconocido < 6.3.1 6.3.1 2022-03-10 ✓ corregido en la última versión
WooCommerce [woocommerce] < 6.3.1 Desconocido < 6.3.1 6.3.1 2022-03-10 ✓ corregido en la última versión
WooCommerce [woocommerce] < 6.2.1 Desconocido < 6.2.1 6.2.1 2022-02-23 ✓ corregido en la última versión
WooCommerce [woocommerce] < 6.2.1 Desconocido < 6.2.1 6.2.1 2022-02-23 ✓ corregido en la última versión
WooCommerce [woocommerce] < 6.2.1 Desconocido < 6.2.1 6.2.1 2022-02-22 ✓ corregido en la última versión
WooCommerce [woocommerce] < 6.2.1 Desconocido < 6.2.1 6.2.1 2022-02-22 ✓ corregido en la última versión
WooCommerce [woocommerce] < 5.7.0 Desconocido < 5.7.0 5.7.0 2021-09-22 ✓ corregido en la última versión
WooCommerce [woocommerce] < 5.5.1 Desconocido < 5.5.1 5.5.1 2021-07-15 ✓ corregido en la última versión
CVE-2021-32790 WooCommerce [woocommerce] < 6.6.0 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Media 4,9 < 6.6.0 6.6.0 2021-07-13 ✓ corregido en la última versión
WooCommerce [woocommerce] < 5.2.0 Desconocido < 5.2.0 5.2.0 2021-04-29 ✓ corregido en la última versión
CVE-2021-24323 WooCommerce [woocommerce] < 5.2.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 5.2.0 5.2.0 2021-04-21 ✓ corregido en la última versión
WooCommerce [woocommerce] < 4.6.2 Desconocido < 4.6.2 4.6.2 2020-11-06 ✓ corregido en la última versión
WooCommerce [woocommerce] < 4.6.2 Desconocido < 4.6.2 4.6.2 2020-11-05 ✓ corregido en la última versión
WooCommerce [woocommerce] < 4.2.1 Desconocido < 4.2.1 4.2.1 2020-06-22 ✓ corregido en la última versión
WooCommerce [woocommerce] < 4.1.0 Desconocido < 4.1.0 4.1.0 2020-05-05 ✓ corregido en la última versión
CVE-2020-29156 WooCommerce [woocommerce] < 4.7.0 Elusión de autorización mediante una clave controlada por el usuario Media 5,3 < 4.7.0 4.7.0 2020-01-21 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.6.5 Desconocido < 3.6.5 3.6.5 2019-07-07 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.6.5 Desconocido < 3.6.5 3.6.5 2019-07-02 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.6.5 Desconocido < 3.6.5 3.6.5 2019-07-02 ✓ corregido en la última versión
CVE-2019-9168 WooCommerce [woocommerce] < 3.5.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.5.5 3.5.5 2019-02-20 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.5.1 Desconocido < 3.5.1 3.5.1 2019-01-07 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.4.6 Desconocido < 3.4.6 3.4.6 2018-12-11 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.5.2 Desconocido < 3.5.2 3.5.2 2018-11-29 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.4.6 Desconocido < 3.4.6 3.4.6 2018-11-07 ✓ corregido en la última versión
CVE-2018-20714 WooCommerce [woocommerce] < 3.4.6 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 8,1 < 3.4.6 3.4.6 2018-11-06 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.4.6 Desconocido < 3.4.6 3.4.6 2018-10-29 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.4.5 Desconocido < 3.4.5 3.4.5 2018-09-01 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.4.5 Desconocido < 3.4.5 3.4.5 2018-08-29 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.2.4 Desconocido < 3.2.4 3.2.4 2018-02-23 ✓ corregido en la última versión
CVE-2017-17058 WooCommerce [woocommerce] < 4.0 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 7,5 < 4.0 4.0 2017-11-29 ✓ corregido en la última versión
CVE-2017-18356 WooCommerce [woocommerce] < 3.2.4 Control incorrecto de la generación de código (inyección de código) Alta 8,8 < 3.2.4 3.2.4 2017-11-16 ✓ corregido en la última versión
CVE-2016-10112 WooCommerce [woocommerce] < 2.6.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 2.6.9 2.6.9 2016-12-07 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.6.4 Desconocido < 2.6.4 2.6.4 2016-09-09 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.6.4 Desconocido < 2.6.4 2.6.4 2016-07-26 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.6.3 Desconocido < 2.6.3 2.6.3 2016-07-20 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.6.3 Desconocido < 2.6.3 2.6.3 2016-07-19 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.4.9 Desconocido < 2.4.9 2.4.9 2015-11-17 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.4.9 Desconocido < 2.4.9 2.4.9 2015-11-17 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.3.11 Desconocido < 2.3.11 2.3.11 2015-06-17 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.2.3 Desconocido < 2.2.3 2.2.3 2015-06-10 ✓ corregido en la última versión
WooCommerce [woocommerce] >= 2.0.20 - <= 2.3.10 Desconocido 2.0.20–2.3.10 2.3.10 2015-06-10 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.0.18 Desconocido < 2.0.18 2.0.18 2015-05-15 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.0.13 Desconocido < 2.0.13 2.0.13 2015-05-15 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.3.6 Desconocido < 2.3.6 2.3.6 2015-05-15 ✓ corregido en la última versión
CVE-2015-2329 WooCommerce [woocommerce] >= 2.3 - <= 2.3.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 2.3–2.3.5 2.3.5 2015-03-13 ✓ corregido en la última versión
CVE-2015-2069 WooCommerce [woocommerce] < 2.2.11 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 2.2.11 2.2.11 2015-01-29 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.2.3 Desconocido < 2.2.3 2.2.3 2014-09-17 ✓ corregido en la última versión
CVE-2014-6313 WooCommerce [woocommerce] < 2.2.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 2.2.3 2.2.3 2014-09-11 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.0.18 Desconocido < 2.0.18 2.0.18 2013-10-17 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.0.13 Desconocido < 2.0.13 2.0.13 2013-07-18 ✓ corregido en la última versión
WooCommerce [woocommerce] < 9.3.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 9.3.4 9.3.4 0000-00-00 ✓ corregido en la última versión
CVE-2026-3589 WooCommerce [woocommerce] < 10.5.3 Desconocido < 10.5.3 10.5.3 0000-00-00 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.2.3 Desconocido < 2.2.3 2.2.3 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.0.13 Desconocido < 2.0.13 2.0.13 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.0.17 Desconocido < 2.0.17 2.0.17 ✓ corregido en la última versión
WooCommerce [woocommerce] < 6.2.1 Desconocido < 6.2.1 6.2.1 ✓ corregido en la última versión
WooCommerce [woocommerce] < 5.7.0 Desconocido < 5.7.0 5.7.0 ✓ corregido en la última versión
WooCommerce [woocommerce] < 5.7.0 Desconocido < 5.7.0 5.7.0 ✓ corregido en la última versión
WooCommerce [woocommerce] < 4.6.2 Desconocido < 4.6.2 4.6.2 ✓ corregido en la última versión
WooCommerce [woocommerce] < 4.2.1 Desconocido < 4.2.1 4.2.1 ✓ corregido en la última versión
WooCommerce [woocommerce] < 4.1.0 Desconocido < 4.1.0 4.1.0 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.6.5 Desconocido < 3.6.5 3.6.5 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.5.1 Desconocido < 3.5.1 3.5.1 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.4.6 Desconocido < 3.4.6 3.4.6 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.4.6 Desconocido < 3.4.6 3.4.6 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.4.6 Desconocido < 3.4.6 3.4.6 ✓ corregido en la última versión
WooCommerce [woocommerce] < 3.4.5 Desconocido < 3.4.5 3.4.5 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.6.4 Desconocido < 2.6.4 2.6.4 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.4.9 Desconocido < 2.4.9 2.4.9 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.3.11 Desconocido < 2.3.11 2.3.11 ✓ corregido en la última versión
WooCommerce [woocommerce] < 2.6.3 Desconocido < 2.6.3 2.6.3 ✓ corregido en la última versión
WooCommerce [woocommerce] < 7.0.1 Desconocido < 7.0.1 7.0.1 ✓ corregido en la última versión
WooCommerce [woocommerce] < 7.9 Desconocido < 7.9 7.9 ✓ corregido en la última versión
WooCommerce [woocommerce] < 7.0.1 Desconocido < 7.0.1 7.0.1 ✓ corregido en la última versión
WooCommerce [woocommerce] < 7.9.0 Desconocido < 7.9.0 7.9.0 ✓ corregido en la última versión
WooCommerce [woocommerce] < 8.4.0 Desconocido < 8.4.0 8.4.0 ✓ corregido en la última versión
WooCommerce [woocommerce] < 8.4.0 Desconocido < 8.4.0 8.4.0 ✓ corregido en la última versión

WooCommerce [woocommerce] < 8.9.3

<p>WordPress WooCommerce Plugin <= 8.9.2 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: WooCommerce</p><p>Link: https://wordpress.org/plugins/woocommerce/#developers</p><p>Affected Version <= 8.9.2</p><p>Fixed in version 8.9.3 </p>

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-37297

WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While the content is not saved to the database, the links may be sent to victims for malicious purposes. The injected JavaScript could hijack content & data stored in the browser, including the session. The URL content is read through the `Sourcebuster.js` library and then inserted without proper sanitization to the classic checkout and registration forms. Versions 8.8.5 and 8.9.3 contain a patch for the issue. As a workaround, one may disable the Order Attribution feature.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-22155

Update the WordPress WooCommerce plugin to the latest available version (at least 8.6.0). Dhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WooCommerce Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 8.6.0. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1310

The WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to insufficient restrictions in the product shortcode in all versions up to, and including, 8.5.2. This makes it possible for authenticated attackers, with contributor-level access and above, to view private and draft products.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-0775

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WooCommerce [woocommerce] < 8.4.0

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions before 8.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. IMPORTANT: There was a miscommunication and error in this vulnerability record where we initially reported version 8.5.0 as patched, while 8.4.0 was still vulnerable. This issue was patched in version 8.4.0 and only affects versions up to 8.3.0. Please rest assured knowing you can update the plugin to version 8.4.0 and this issue will be patched.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-52222

Update the WordPress WooCommerce plugin to the latest available version (at least 8.3.0). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WooCommerce Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 8.3.0. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-47777

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a featured image 'alt' attribute in versions up to, and including, 8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The WooCommerce Blocks plugin for WordPress is vulnerable to the same issue in versions up to, and including, 11.1.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 7.0.1

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.0. This can allow authenticated attackers with Shop Manager privileges or above to extract sensitive user metadata including session tokens.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 7.9.0

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information including PII(Personal Identifiable Information).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-2099

The WooCommerce plugin for WordPress is vulnerable to Stored HTML Injection via payment gateway titles in versions up to 6.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with high-level capabilities, such as a Store Manager, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 5.7.0

The WooCommerce and WooCommerce Admin plugins for WordPress are vulnerable to Sensitive Data Exposure in versions up to 5.7.0 for WooCommerce and 2.6.4 for WooCommerce Admin due to insufficient protection of analytic report storage in the directory they are stored. This makes it possible for attackers to extract sensitive data related to report analytics on certain host configurations.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 6.3.1

Orders Status Change (via PayPal Standard Gateway) vulnerability discovered in WordPress WooCommerce plugin (versions <= 6.3.0).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 6.3.1

The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce check on the PayPal order updates functionality in versions up to, and including, 6.3.0. This makes it possible for authenticated attackers to change the status of arbitrary orders that have been created with PayPal.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 6.2.1

Path Traversal via Importers vulnerability discovered in WordPress WooCommerce plugin (versions <= 6.2.0).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 6.2.1

Arbitrary Comment Deletion vulnerability discovered in WordPress WooCommerce plugin (versions <= 6.2.0).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 6.2.1

The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on the /wc/v2/products/ REST API in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers with minimal permissions such as a subscriber to delete, edit, and read arbitrary comments and reviews.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 6.2.1

The WooCommerce plugin for WordPress is vulnerable to path traversal via the 'file_url' parameter found in the importers functionality in versions up to, and including, 6.2.0. This makes it possible for authenticated attackers, with high-level permissions such as an administrator, to access files outside of the intended directory when performing an import.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 5.7.0

Analytics Report Leaks vulnerability discovered in the WordPress WooCommerce plugin (versions <= 5.6.0).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 5.5.1

Unauthenticated SQL Injection (SQLi) vulnerability discovered in WordPress WooCommerce plugin (versions <= 5.5.0).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-32790

Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `/wp-json/wc/v3/webhooks`, `/wp-json/wc/v2/webhooks` and other webhook listing API. Read-only SQL queries can be executed using this exploit, while data will not be returned, by carefully crafting `search` parameter information can be disclosed using timing and related attacks. Version 3.3.6 is the earliest version of Woocommerce with a patch for this vulnerability. There are no known workarounds other than upgrading.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WooCommerce [woocommerce] < 5.2.0

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress WooCommerce plugin (versions <= 5.1.0).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24323

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Additional tax classes' field when the tax functionality of WooCommerce is enabled in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 4.6.2

Guest Account Creation vulnerability found in WordPress WooCommerce plugin (versions <= 4.6.1).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 4.6.2

The WooCommerce plugin for WordPress is vulnerable to unauthorized user account creation during checkout even when the “Allow customers to create an account during checkout” setting is disabled. was disabled due to missing authorization checks in versions up to and including 4.6.1. The WooCommerce Blocks plugin for WordPress is vulnerable to the same issue in versions up to, and including, 3.7.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 4.2.1

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing sanitization and escaping in SelectWoo, that makes it possible for attackers to inject arbitrary web scripts. This affects versions up to 4.2.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 4.1.0

The WooCommerce plugin for WordPress is vulnerable to arbitrary product meta data creation/overwriting due to a lack of escaping and validation on the post meta data being supplied during product duplication in versions up to, and including 4.0.4. This makes it possible for authenticated attackers, with product duplicating capabilities, to modify post meta that could potential be used to achieve remote code execution.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2020-29156

"The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action."

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 3.6.5

Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WooCommerce plugin (versions <= 3.6.4).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 3.6.5

The WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads via the tax rate importer due to missing file type validation that made it possible for high level authenticated attackers to upload malicious files in versions up to, and including, 3.6.4.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 3.6.5

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 3.6.4, due to the CSV importer actions missing a nonce validation. This makes it possible for attackers with at least author privileges to embed script code in a CSV, upload it to the target site, and then trick an administrator into uploading the CSV injected payload to a product description via a forged request all granted they can trick them into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2019-9168

Stored Cross-Site Scripting (XSS) vulnerability found by Fortinet's FortiGuard Labs (Zhouyuan Yang) in WordPress WooCommerce plugin (versions <= 3.5.4).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 3.5.1

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Ripstech in WordPress WooCommerce plugin (versions <= 3.5.0).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 3.4.6

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found in WordPress WooCommerce plugin (versions <= 3.4.5).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 3.5.2

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting due to sanitization and escaping on an unspecific variable, that makes it possible for attackers to inject arbitrary web scripts into pages. This affects versions up to 3.5.0, and can be exploited by users with write-access API keys.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 3.4.6

Authenticated File Deletion to Privilege Escalation vulnerability found in WordPress WooCommerce plugin (versions <= 3.4.5).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2018-20714

The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WooCommerce [woocommerce] < 3.4.6

Authenticated Object Injection vulnerability found by Slavco in WordPress WooCommerce plugin (versions <= 3.4.5).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 3.4.5

According to WooCommerce, versions, 3.4.4 and earlier are affected by an issue where a function that updates attributes could lead to object injection, related to the WordPress 4.8.3 security release.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 3.4.5

The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection by users with access to edit attributes in versions up to, and including 3.4.4.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 3.2.4

Authenticated PHP Object Injection vulnerability found in WordPress WooCommerce plugin (versions <=3.2.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2017-17058

The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traversal is not possible because all of the template files have "if (!defined('ABSPATH')) {exit;}" code

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2017-18356

In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2016-10112

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WooCommerce [woocommerce] < 2.6.4

This plugin is prone to stored cross site scripting vulnerability via REST API. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 2.6.4

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image uploader feature powered by the /wc-api/v3/products/categories/ REST-API in versions up to, and including, 2.6.3 due to insufficient filetype validation. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 2.6.3

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 2.6.3

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image EXIF metadata in versions up to, and including, 2.6.2 due to insufficient validation on image files EXIF content. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 2.4.9

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 2.4.9

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the pay_price() function, in versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 2.3.11

This plugin has a PHP bug which allows to download critical files. Attacker can access to these files and compromise site. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 2.2.3

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] >= 2.0.20 - <= 2.3.10

The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.10 via deserialization of untrusted input from the $custom parameter. This allows authenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to exploit XXE and read sensitive files from the server.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 2.0.18

his plugin is prone to a cross site scripting vulnerability via hide-wc-extensions-message parameter. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 2.0.13

This plugin is prone to a cross site scripting vulnerability via index.php calc_shipping_state parameter. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 2.3.6

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2015-2329

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2015-2069

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WooCommerce [woocommerce] < 2.2.3

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2014-6313

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin/admin.php.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WooCommerce [woocommerce] < 2.0.18

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.17 via the 'hide-wc-extensions-message' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser session.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 2.0.13

The WooCommerce plugin for WordPress is vulnerable to Self-Reflected Cross-Site Scripting in versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 9.3.4

The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' page in all versions up to, and including, 9.4.2 due to insufficient input sanitization and output escaping on PostMessage data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-3589

The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 10.5.3 (exclusive). This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WooCommerce [woocommerce] < 2.2.3

The WooCommerce WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 2.0.13

The WooCommerce WordPress plugin was affected by an index.php calc_shipping_state Parameter XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 2.0.17

The WooCommerce WordPress plugin was affected by a hide-wc-extensions-message Parameter Reflected XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 6.2.1

The PayPal Standard payment gateway (deprecated since July 2021) of the plugin could allow attackers to mark an order as paid without actually making a payment, when PDT is enabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 5.7.0

The plugin does not properly check for path traversal when importing tax rates. There are limited details at this stage and this advisory will be updated later on

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 5.7.0

The plugin was vulnerable to Analytics Report Leaks on some hosting configurations. As well as updating WooCommerce to at least version 5.7.0, and WooCommerce Admin to at least version 2.6.4, it is also recommended that directory listing is disabled on your host. Automattic updates were rolled out to force the vulnerable plugins to be updated and patched.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 4.6.2

Versions of WooCommerce prior to 4.6.2 contain a vulnerability that allows guest users to create accounts during checkout even when the "Allow customers to create an account during checkout" setting is disabled. This vulnerability is being exploited by a bot to place spam orders and create user accounts that are then used to probe for vulnerabilities in other plugins on the site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 4.2.1

A DOM based Cross-Site Scripting (XSS) vulnerability was found to affect the SelectWoo dependency that WooCommerce used. SelectWoo replaces the standard <select> box in web browsers.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 4.1.0

The WooCommerce changelog file was updated with the following message: "Security – Fixed unescaped meta data while duplicating products. Reported by Slavco." We will update this issue with further information as it becomes available.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 3.6.5

Changelog mentions: Security – Introduce file type check for tax rate importer. Security – Added nonce check to CSV importer actions. RIPS Tech later released an advisory detailing the vulnerability, which can be found in the references.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 3.5.1

The WooCommerce WordPress plugin was affected by an Authenticated Stored XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 3.4.6

The WooCommerce WordPress plugin was affected by an Authenticated Phar Deserialization security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 3.4.6

The WooCommerce WordPress plugin was affected by an Authenticated Stored XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 3.4.6

According to WooCommerce: "Versions 3.4.5 and earlier are affected by a handful of issues that allow Shop Managers to exceed their capabilities and perform malicious actions. These issues can be exploited by users with Shop Manager capabilities or greater, and we recommend all users running WooCommerce 3.x upgrade to 3.4.6 to mitigate them. Thanks to Simon Scannell, Karim, and Slavco for reporting the issues." See references for PoC and further technical details.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 3.4.5

According to WooCommerce: "Versions 3.4.4 and earlier are affected by an issue where a function that updates attributes could lead to object injection. This is related to the WordPress 4.8.3 security release. This issue can only be exploited by users who can edit attributes and should not be possible to exploit through the WordPress administrative screens, but we still recommend all users running WooCommerce 3.x upgrade to 3.4.5 to mitigate this issue. Thanks to slavco for responsibly disclosing the vulnerability to us."

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 2.6.4

The WooCommerce WordPress plugin was affected by a Stored Cross Site Scripting (XSS) via REST API security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 2.4.9

The WooCommerce WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 2.3.11

According to the researcher: The vulnerability is only present when WooCommerce’s "PayPal Identity Token" option is set.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 2.6.3

The WooCommerce WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 7.0.1

The plugin returns all user metadata via an AJAX action, which could allow users with a role as low as Shop Manager to access an arbitrary user's metadata which could include tokens and other potentially sensitive data

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 7.9

The plugin does not properly apply CORS on some of its API endpoints, allowing attackers to leak customers PII information.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 7.0.1

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.0. This can allow authenticated attackers with Shop Manager privileges or above to extract sensitive user metadata including session tokens.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 7.9.0

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the Store API's REST endpoints allowing direct external access from any origin. This can allow unauthenticated attackers to extract sensitive user information including PII(Personal Identifiable Information).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WooCommerce [woocommerce] < 8.4.0

Update the WordPress WooCommerce plugin to the latest available version (at least 8.4.0). An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WooCommerce Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 8.4.0. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WooCommerce [woocommerce] < 8.4.0

The plugin does not properly sanitize user-input provided by the add_query_arg() function when echoed back into JavaScript code context.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén WooCommerce actualizado — 10.9.4 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.