PLUGIN SECURITY
Is WooCommerce safe?
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
What this plugin does
- Slug:
woocommerce - Author: Automattic
- 7000000+ active installs
- 90/100 rating (4819 reviews on wordpress.org)
- 459175020 all-time downloads
- On WordPress.org since 2011-09-27
ecommerceonline storesell onlineshopshopping cart
Maintenance status
- Latest known version: 11.0.0
- Last updated: 2026-08-10 5:53pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
27 known CVEs on file for WooCommerce.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2022-50972 | WooCommerce [woocommerce] == 7.1.0 (unfixed) | — | Critical 9.8 | < 7.1.0 | 7.1.0 | 2026-06-20 | ✓ fixed in latest |
| CVE-2025-15033 | WooCommerce [woocommerce] < 10.4.3 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 6.5 | < 10.4.3 | 10.4.3 | 2025-12-22 | ✓ fixed in latest |
| CVE-2025-49042 | WooCommerce [woocommerce] < 10.0.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 10.0.3 | 10.0.3 | 2025-10-29 | ✓ fixed in latest |
| CVE-2025-26762 | WooCommerce [woocommerce] < 9.7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 9.7.1 | 9.7.1 | 2025-03-12 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 9.4.3 | — | Unknown | < 9.4.3 | 9.4.3 | 2024-12-04 | ✓ fixed in latest |
| CVE-2024-9944 | WooCommerce [woocommerce] < 9.1.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 9.1.0 | 9.1.0 | 2024-10-14 | ✓ fixed in latest |
| CVE-2024-39666 | WooCommerce [woocommerce] < 9.1.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 9.1.4 | 9.1.4 | 2024-08-16 | ✓ fixed in latest |
| CVE-2024-35777 | WooCommerce [woocommerce] < 9.0.0 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | Low 3.5 | < 9.0.0 | 9.0.0 | 2024-06-27 | ✓ fixed in latest |
+ 119 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | WooCommerce [woocommerce] < 8.9.3 | — | Unknown | < 8.9.3 | 8.9.3 | 2024-06-11 | ✓ fixed in latest |
| CVE-2024-37297 | WooCommerce [woocommerce] < 8.9.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 8.9.3 | 8.9.3 | 2024-06-10 | ✓ fixed in latest |
| CVE-2024-22155 | WooCommerce [woocommerce] < 8.6.0 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 8.6.0 | 8.6.0 | 2024-04-05 | ✓ fixed in latest |
| CVE-2024-1310 | WooCommerce [woocommerce] < 8.6 | Improper Access Control | Medium 4.9 | < 8.6 | 8.6 | 2024-03-25 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 8.4.0 | — | Unknown | < 8.4.0 | 8.4.0 | 2024-01-12 | ✓ fixed in latest |
| CVE-2023-52222 | WooCommerce [woocommerce] < 8.3.0 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 8.3.0 | 8.3.0 | 2024-01-05 | ✓ fixed in latest |
| CVE-2023-47777 | WooCommerce [woocommerce] < 8.2.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 8.2.0 | 8.2.0 | 2023-11-15 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 7.0.1 | — | Unknown | < 7.0.1 | 7.0.1 | 2023-09-11 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 7.9.0 | — | Unknown | < 7.9.0 | 7.9.0 | 2023-09-11 | ✓ fixed in latest |
| CVE-2022-2099 | WooCommerce [woocommerce] < 6.6.0 | Improper Encoding or Escaping of Output | Medium 4.8 | < 6.6.0 | 6.6.0 | 2022-06-20 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 5.7.0 | — | Unknown | < 5.7.0 | 5.7.0 | 2022-04-10 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 6.3.1 | — | Unknown | < 6.3.1 | 6.3.1 | 2022-03-10 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 6.3.1 | — | Unknown | < 6.3.1 | 6.3.1 | 2022-03-10 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2022-02-23 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2022-02-23 | ✓ fixed in latest |
| CVE-2022-0775 | WooCommerce [woocommerce] < 6.2.1 | Incorrect Authorization | Medium 4.3 | < 6.2.1 | 6.2.1 | 2022-02-22 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2022-02-22 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 5.7.0 | — | Unknown | < 5.7.0 | 5.7.0 | 2021-09-22 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 5.5.1 | — | Unknown | < 5.5.1 | 5.5.1 | 2021-07-15 | ✓ fixed in latest |
| CVE-2021-32790 | WooCommerce [woocommerce] < 6.6.0 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 4.9 | < 6.6.0 | 6.6.0 | 2021-07-13 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 5.2.0 | — | Unknown | < 5.2.0 | 5.2.0 | 2021-04-29 | ✓ fixed in latest |
| CVE-2021-24323 | WooCommerce [woocommerce] < 5.2.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 5.2.0 | 5.2.0 | 2021-04-21 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 4.6.2 | — | Unknown | < 4.6.2 | 4.6.2 | 2020-11-06 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 4.6.2 | — | Unknown | < 4.6.2 | 4.6.2 | 2020-11-05 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 4.2.1 | — | Unknown | < 4.2.1 | 4.2.1 | 2020-06-22 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 4.1.0 | — | Unknown | < 4.1.0 | 4.1.0 | 2020-05-05 | ✓ fixed in latest |
| CVE-2020-29156 | WooCommerce [woocommerce] < 4.7.0 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 4.7.0 | 4.7.0 | 2020-01-21 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.6.5 | — | Unknown | < 3.6.5 | 3.6.5 | 2019-07-07 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.6.5 | — | Unknown | < 3.6.5 | 3.6.5 | 2019-07-02 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.6.5 | — | Unknown | < 3.6.5 | 3.6.5 | 2019-07-02 | ✓ fixed in latest |
| CVE-2019-9168 | WooCommerce [woocommerce] < 3.5.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.5.5 | 3.5.5 | 2019-02-20 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.5.1 | — | Unknown | < 3.5.1 | 3.5.1 | 2019-01-07 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.4.6 | — | Unknown | < 3.4.6 | 3.4.6 | 2018-12-11 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.5.2 | — | Unknown | < 3.5.2 | 3.5.2 | 2018-11-29 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.4.6 | — | Unknown | < 3.4.6 | 3.4.6 | 2018-11-07 | ✓ fixed in latest |
| CVE-2018-20714 | WooCommerce [woocommerce] < 3.4.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.1 | < 3.4.6 | 3.4.6 | 2018-11-06 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.4.6 | — | Unknown | < 3.4.6 | 3.4.6 | 2018-10-29 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.4.5 | — | Unknown | < 3.4.5 | 3.4.5 | 2018-09-01 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.4.5 | — | Unknown | < 3.4.5 | 3.4.5 | 2018-08-29 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.2.4 | — | Unknown | < 3.2.4 | 3.2.4 | 2018-02-23 | ✓ fixed in latest |
| CVE-2017-17058 | WooCommerce [woocommerce] < 4.0 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.5 | < 4.0 | 4.0 | 2017-11-29 | ✓ fixed in latest |
| CVE-2017-18356 | WooCommerce [woocommerce] < 3.2.4 | Improper Control of Generation of Code ('Code Injection') | High 8.8 | < 3.2.4 | 3.2.4 | 2017-11-16 | ✓ fixed in latest |
| CVE-2016-10112 | WooCommerce [woocommerce] < 2.6.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 2.6.9 | 2.6.9 | 2016-12-07 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.6.4 | — | Unknown | < 2.6.4 | 2.6.4 | 2016-09-09 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.6.4 | — | Unknown | < 2.6.4 | 2.6.4 | 2016-07-26 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.6.3 | — | Unknown | < 2.6.3 | 2.6.3 | 2016-07-20 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.6.3 | — | Unknown | < 2.6.3 | 2.6.3 | 2016-07-19 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.4.9 | — | Unknown | < 2.4.9 | 2.4.9 | 2015-11-17 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.4.9 | — | Unknown | < 2.4.9 | 2.4.9 | 2015-11-17 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.3.11 | — | Unknown | < 2.3.11 | 2.3.11 | 2015-06-17 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.2.3 | — | Unknown | < 2.2.3 | 2.2.3 | 2015-06-10 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] >= 2.0.20 - <= 2.3.10 | — | Unknown | 2.0.20–2.3.10 | 2.3.10 | 2015-06-10 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.0.18 | — | Unknown | < 2.0.18 | 2.0.18 | 2015-05-15 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.0.13 | — | Unknown | < 2.0.13 | 2.0.13 | 2015-05-15 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.3.6 | — | Unknown | < 2.3.6 | 2.3.6 | 2015-05-15 | ✓ fixed in latest |
| CVE-2015-2329 | WooCommerce [woocommerce] >= 2.3 - <= 2.3.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | 2.3–2.3.6 | 2.3.6 | 2015-03-13 | ✓ fixed in latest |
| CVE-2015-2069 | WooCommerce [woocommerce] < 2.2.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 2.2.11 | 2.2.11 | 2015-01-29 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.2.3 | — | Unknown | < 2.2.3 | 2.2.3 | 2014-09-17 | ✓ fixed in latest |
| CVE-2014-6313 | WooCommerce [woocommerce] < 2.2.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 2.2.3 | 2.2.3 | 2014-09-11 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.0.18 | — | Unknown | < 2.0.18 | 2.0.18 | 2013-10-17 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.0.13 | — | Unknown | < 2.0.13 | 2.0.13 | 2013-07-18 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 9.3.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 9.3.4 | 9.3.4 | 0000-00-00 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 10.5.3 | — | Unknown | < 10.5.3 | 10.5.3 | 0000-00-00 | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.2.3 | — | Unknown | < 2.2.3 | 2.2.3 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.0.13 | — | Unknown | < 2.0.13 | 2.0.13 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.0.17 | — | Unknown | < 2.0.17 | 2.0.17 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 5.7.0 | — | Unknown | < 5.7.0 | 5.7.0 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 5.7.0 | — | Unknown | < 5.7.0 | 5.7.0 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 4.6.2 | — | Unknown | < 4.6.2 | 4.6.2 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 4.2.1 | — | Unknown | < 4.2.1 | 4.2.1 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 4.1.0 | — | Unknown | < 4.1.0 | 4.1.0 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.6.5 | — | Unknown | < 3.6.5 | 3.6.5 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.5.1 | — | Unknown | < 3.5.1 | 3.5.1 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.4.6 | — | Unknown | < 3.4.6 | 3.4.6 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.4.6 | — | Unknown | < 3.4.6 | 3.4.6 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.4.6 | — | Unknown | < 3.4.6 | 3.4.6 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 3.4.5 | — | Unknown | < 3.4.5 | 3.4.5 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.6.4 | — | Unknown | < 2.6.4 | 2.6.4 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.4.9 | — | Unknown | < 2.4.9 | 2.4.9 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.3.11 | — | Unknown | < 2.3.11 | 2.3.11 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 2.6.3 | — | Unknown | < 2.6.3 | 2.6.3 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 7.0.1 | — | Unknown | < 7.0.1 | 7.0.1 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 7.9 | — | Unknown | < 7.9 | 7.9 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 7.0.1 | — | Unknown | < 7.0.1 | 7.0.1 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 7.9.0 | — | Unknown | < 7.9.0 | 7.9.0 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 8.4.0 | — | Unknown | < 8.4.0 | 8.4.0 | — | ✓ fixed in latest |
| — | WooCommerce [woocommerce] < 8.4.0 | — | Unknown | < 8.4.0 | 8.4.0 | — | ✓ fixed in latest |
| — | WooCommerce 2.0.17 - hide-wc-extensions-message Parameter Reflected XSS | — | Unknown | < 2.0.17 | 2.0.17 | — | ✓ fixed in latest |
| — | WooCommerce 2.0.12 - index.php calc_shipping_state Parameter XSS | — | Unknown | < 2.0.13 | 2.0.13 | — | ✓ fixed in latest |
| — | WooCommerce < 2.2.3 - Reflected Cross-Site Scripting (XSS) | — | Unknown | < 2.2.3 | 2.2.3 | — | ✓ fixed in latest |
| — | WooCommerce 2.0.20-2.3.10 - Object Injection / XXE | — | Unknown | < 2.3.11 | 2.3.11 | — | ✓ fixed in latest |
| — | WooCommerce <= 2.4.8 - Authenticated Cross-Site Scripting (XSS) | — | Unknown | < 2.4.9 | 2.4.9 | — | ✓ fixed in latest |
| — | WooCommerce <= 2.6.2 - Authenticated Cross-Site Scripting (XSS) | — | Unknown | < 2.6.3 | 2.6.3 | — | ✓ fixed in latest |
| — | WooCommerce <= 2.6.3 - Stored Cross Site Scripting (XSS) via REST API | — | Unknown | < 2.6.4 | 2.6.4 | — | ✓ fixed in latest |
| — | WooCommerce <= 3.4.4 - Potential Object Injection | — | Unknown | < 3.4.5 | 3.4.5 | — | ✓ fixed in latest |
| — | WooCommerce <= 3.4.5 - Authenticated Object Injection | — | Unknown | < 3.4.6 | 3.4.6 | — | ✓ fixed in latest |
| — | WooCommerce <= 3.4.5 - Authenticated Stored XSS | — | Unknown | < 3.4.6 | 3.4.6 | — | ✓ fixed in latest |
| — | WooCommerce <= 3.4.5 - Authenticated Phar Deserialization | — | Unknown | < 3.4.6 | 3.4.6 | — | ✓ fixed in latest |
| — | WooCommerce <= 3.5.0 - Authenticated Stored XSS | — | Unknown | < 3.5.1 | 3.5.1 | — | ✓ fixed in latest |
| — | WooCommerce <= 3.6.4 - Cross-Site Request Forgery (CSRF) & File Type Check | — | Unknown | < 3.6.5 | 3.6.5 | — | ✓ fixed in latest |
| — | WooCommerce < 4.1.0 - Unescaped Metadata when Duplicating Products | — | Unknown | < 4.1.0 | 4.1.0 | — | ✓ fixed in latest |
| — | WooCommerce < 4.2.1 - Potential Cross-Site Scripting (XSS) via SelectWoo | — | Unknown | < 4.2.1 | 4.2.1 | — | ✓ fixed in latest |
| — | WooCommerce < 4.6.2 - Guest Account Creation | — | Unknown | < 4.6.2 | 4.6.2 | — | ✓ fixed in latest |
| — | WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Analytics Report Leaks | — | Unknown | < 5.7.0 | 5.7.0 | — | ✓ fixed in latest |
| CVE-2022-0775 | WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion | — | Unknown | < 6.2.1 | 6.2.1 | — | ✓ fixed in latest |
| — | WooCommerce < 6.2.1 - Path Traversal via Importers | — | Unknown | < 6.2.1 | 6.2.1 | — | ✓ fixed in latest |
| — | WooCommerce < 6.3.1 - Orders Marked as Paid (via PayPal Standard Gateway) | — | Unknown | < 6.3.1 | 6.3.1 | — | ✓ fixed in latest |
| — | WooCommerce < 7.9 - Unauthenticated Sensitive Information Disclosure | — | Unknown | < 7.9 | 7.9 | — | ✓ fixed in latest |
| — | WooCommerce < 8.1.1 - Shop Manager+ User Metadata Disclosure | — | Unknown | < 8.1.1 | 8.1.1 | — | ✓ fixed in latest |
| — | WooCommerce < 7.9.0 - Sensitive Information Exposure | — | Unknown | < 7.9.0 | 7.9.0 | — | ✓ fixed in latest |
| — | WooCommerce < 7.0.1 - Authenticated(Shop Manager+) Sensitive Information Exposure | — | Unknown | < 7.0.1 | 7.0.1 | — | ✓ fixed in latest |
| — | WooCommerce < 8.4.0 - Reflected Cross-Site Scripting | — | Unknown | < 8.4.0 | 8.4.0 | — | ✓ fixed in latest |
| — | WooCommerce < 9.2 - Contributor+ Stored XSS | — | Unknown | < 9.2 | 9.2 | — | ✓ fixed in latest |
| CVE-2025-5062 | WooCommerce < 9.4.3 - Reflected XSS | — | Unknown | < 9.4.3 | 9.4.3 | — | ✓ fixed in latest |
| — | WooCommerce < 9.4.3 - Unauthenticated Order Creation | — | Unknown | < 9.4.3 | 9.4.3 | — | ✓ fixed in latest |
| — | Wocommerce < 9.9.4 - Shop manager+ SQLi | — | Unknown | < 9.9.4 | 9.9.4 | — | ✓ fixed in latest |
| — | WooCommerce < 10.0 - Shop Manager PII Leak in Multisite | — | Unknown | < 10.0 | 10.0 | — | ✓ fixed in latest |
| CVE-2026-3589 | WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF | — | Unknown | < 5.4.4 | 5.4.4 | — | ✓ fixed in latest |
How to fix it
Keep WooCommerce updated — 11.0.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation — 1000000+ active installs — 86/100 (815) — max PHP 8.4
- WooCommerce PayPal Payments — 800000+ active installs — 56/100 (577) — max PHP 8.4
- Mailchimp for WooCommerce — 200000+ active installs — 80/100 (725) — max PHP 8.4
- WPML Multilingual & Multicurrency for WooCommerce — 100000+ active installs — 84/100 (452)
- Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress — 100000+ active installs — 62/100 (937)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.