PLUGIN SECURITY
Is Booster Plus for WooCommerce safe?
Google Search Console in WordPress: keyword insights, on-page SEO, internal links. AI via WordPress 7 Connectors.
What this plugin does
- Slug:
booster-plus-for-woocommerce - Author: cleverplugins
- 1000+ active installs
- 96/100 rating (54 reviews on wordpress.org)
- 201640 all-time downloads
- On WordPress.org since 2017-06-26
analyticsgoogle search consoleinternal linksseowoocommerce
Maintenance status
- Last updated: 2026-08-06 1:48pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
9 known CVEs on file for Booster Plus for WooCommerce. Reported between 2022 and 2025.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-39446 | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 7.2.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 7.2.5 | 7.2.5 | 2025-04-17 | — |
| CVE-2023-52232 | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 7.1.2 | Missing Authorization | Medium 6.5 | < 7.1.2 | 7.1.2 | 2024-01-05 | — |
| CVE-2023-52230 | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 7.1.3 | Missing Authorization | Medium 6.5 | < 7.1.3 | 7.1.3 | 2024-01-05 | — |
| CVE-2023-52231 | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 7.1.2 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 6.5 | < 7.1.2 | 7.1.2 | 2024-01-05 | — |
| CVE-2022-4017 | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.1 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 6.0.1 | 6.0.1 | 2023-01-02 | — |
| CVE-2022-4227 | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 6.0.0 | 6.0.0 | 2022-12-05 | — |
| CVE-2022-4016 | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.6 | Cross-Site Request Forgery (CSRF) | Medium 6.5 | < 5.6.6 | 5.6.6 | 2022-11-21 | — |
| CVE-2022-3763 | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5 | Cross-Site Request Forgery (CSRF) | High 8.1 | < 5.6.5 | 5.6.5 | 2022-10-31 | — |
+ 4 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2022-3762 | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 5.6.5 | 5.6.5 | 2022-10-27 | — |
| — | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.1 | — | Unknown | < 5.6.1 | 5.6.1 | 2022-09-19 | — |
| — | Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 5.6.1 | — | Unknown | < 5.6.1 | 5.6.1 | — | — |
| — | Booster for WooCommerce - Subscriber+ Order Status Update | — | Unknown | < 5.6.1 | 5.6.1 | — | — |
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Site Kit by Google – Analytics, Search Console, AdSense, Speed — 5000000+ active installs — 84/100 (1009)
- Rank Math SEO – AI SEO Tools to Dominate SEO Rankings — 4000000+ active installs — 96/100 (7493) — max PHP 8.4
- MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) — 2000000+ active installs — 90/100 (3148) — max PHP 8.4
- WP Statistics – Simple, privacy-friendly Google Analytics alternative — 600000+ active installs — 82/100 (757) — max PHP <8.0
- GA Google Analytics – Connect Google Analytics to WordPress — 400000+ active installs — 98/100 (158) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.