CVE · Medium

CVE-2026-49059 — Meta for WooCommerce [facebook-for-woocommerce] < 3.7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-49059 Meta for WooCommerce [facebook-for-woocommerce] < 3.7.1 URL Redirection to Untrusted Site ('Open Redirect') Medium 4.7 < 3.7.1 3.7.1 2026-05-27

CVE-2026-49059

The Meta for WooCommerce plugin for WordPress contains a vulnerability that allows unauthorized individuals to manipulate user redirects, exploiting a lack of thorough URL verification in the affected versions up to 3.7.0. This flaw enables attackers to redirect users to potentially hazardous websites if they can deceive them into taking specific actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.