PLUGIN SECURITY

Is Woo Variation Swatches safe?

Beautiful Color, Image and Buttons Variation Swatches For WooCommerce Product Attributes

What this plugin does

  • Slug: woo-variation-swatches
  • Author: Emran Ahmed
  • 300000+ active installs
  • 96/100 rating (919 reviews on wordpress.org)
  • 9428908 all-time downloads
  • On WordPress.org since 2017-12-20

variation swatcheswoocommercewoocommerce attributeswoocommerce variationwoocommerce variation swatches

Maintenance status

  • Last updated: 2026-06-08 3:47pm GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 7.4+

Known vulnerabilities

1 known CVE on file for Woo Variation Swatches. Reported between 2019 and 2019.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-14774 Variation Swatches for WooCommerce [woo-variation-swatches] < 1.0.62 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.0.62 1.0.62 2019-08-08

CVE-2019-14774

The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.

Source: CVE.org

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.