Extension WordPress

Vulnérabilités WooCommerce

Cette page rassemble les failles publiées pour WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

44Vulnérabilités
0Critiques
44Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WooCommerce

44 fiches

CVE-2025-15033 Moyenne · 4,3
WooCommerce

WooCommerce <= 10.4.2 – Authenticated (Subscriber+) Information Exposure

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.4.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

Versions affectées

10.0-10.0.4, 10.1-10.1.2, 10.2-10.2.2, 10.3-10.3.6, 8.1-8.1.2, 8.2-8.2.3, 8.3-8.3.2, 8.4-8.4.1, 8.5-8.5.3, 8.6-8.6.2, 8.7-8.7.1, 8.8-8.8.5, 8.9-8.9.3, 9.0-9.0.2, 9.1-9.1.4, 9.2-9.2.3, 9.3-9.3.4, 9.4-9.4.3, 9.5-9.5.2, 9.6-9.6.2, 9.7-9.7.1, 9.8-9.8.5, 9.9-9.9.5

Correctif

10.0.5, 10.1.3, 10.2.3, 10.3.7, 8.1.3, 8.2.4, 8.3.3, 8.4.2, 8.5.4, 8.6.3, 8.7.2, 8.8.6, 8.9.4, 9.0.3, 9.1.5, 9.2.4, 9.3.5, 9.4.4, 9.5.3, 9.6.3, 9.7.2, 9.8.6, 9.9.6

Publication

22/12/2025

CVE-2024-39666 Moyenne · 4,4
WooCommerce

WooCommerce <= 9.1.2 – Authenticated (Administrator+) Stored Cross-Site Scripting

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…

Versions affectées

*-9.1.2

Correctif

9.1.3

Publication

16/08/2024

CVE-2024-37297 Moyenne · 6,1
WooCommerce

WooCommerce 8.8.0 – 8.9.2 – Reflected Cross-Site Scripting via Order Attribution

The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via order attribution cookies in versions 8.8.0 to 8.8.4 and 8.9.0 to 8.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

8.8.0-8.8.4, 8.9.0-8.9.2

Correctif

8.8.5, 8.9.3

Publication

10/06/2024

CVE-2023-47777 Moyenne · 6,4
WooCommerce

WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image alt Attribute

The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a featured image 'alt' attribute in versions up to, and including, 8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-8.1.1

Correctif

8.2.0

Publication

15/11/2023

Vulnérabilité Moyenne · 6,5
WooCommerce

WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 – Information Disclosure

The WooCommerce and WooCommerce Admin plugins for WordPress are vulnerable to Sensitive Data Exposure in versions up to 5.7.0 for WooCommerce and 2.6.4 for WooCommerce Admin due to insufficient protection of analytic report storage in the directory they…

Versions affectées

[*, 4.0), [4.0, 4.0.3), [4.1, 4.1.3), [4.2, 4.2.4), [4.3, 4.3.5), [4.4, 4.4.3), [4.5, 4.5.4), [4.6, 4.6.4), [4.7, 4.7.3), [4.8, 4.8.2), [4.9, 4.9.4), [5.0, 5.0.2), [5.1, 5.1.2), [5.2, 5.2.4), [5.3, 5.3.2), [5.4, 5.4.3), [5.5, 5.5.3), [5.6, 5.6.1)

Correctif

4.0.3, 4.1.3, 4.2.4, 4.3.5, 4.4.3, 4.5.4, 4.6.4, 4.7.3, 4.8.2, 4.9.4, 5.0.2, 5.1.2, 5.2.4, 5.3.2, 5.4.3, 5.5.3, 5.6.1, 5.7.0

Publication

10/04/2022

Vulnérabilité Moyenne · 4,3
WooCommerce

WooCommerce < 6.3.1 – Unauthorized Order Status Change

The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce check on the PayPal order updates functionality in versions up to, and including, 6.3.0. This makes it possible for authenticated…

Versions affectées

[3.5, 3.5.10), [3.6, 3.6.7), [3.7, 3.7.3), [3.8, 3.8.3), [3.9, 3.9.5), [4.0, 4.0.4), [4.1, 4.1.4), [4.2, 4.2.5), [4.3, 4.3.6), [4.4, 4.4.4), [4.5, 4.5.5), [4.6, 4.6.5), [4.7, 4.7.4), [4.8, 4.8.3), [4.9, 4.9.5), [5.0, 5.0.3), [5.1, 5.1.3), [5.2, 5.2.5), [5.3, 5.3.3), [5.4, 5.4.4), [5.5, 5.5.4), [5.6, 5.6.2), [5.7, 5.7.2), [5.8, 5.8.1), [5.9, 5.9.1), [6.0, 6.0.1), [6.1, 6.1.2), [6.2, 6.2.2), [6.3, 6.3.1)

Correctif

3.5.10, 3.6.7, 3.7.3, 3.8.3, 3.9.5, 4.0.4, 4.1.4, 4.2.5, 4.3.6, 4.4.4, 4.5.5, 4.6.5, 4.7.4, 4.8.3, 4.9.5, 5.0.3, 5.1.3, 5.2.5, 5.3.3, 5.4.4, 5.5.4, 5.6.2, 5.7.2, 5.8.1, 5.9.1, 6.0.1, 6.1.2, 6.2.2, 6.3.1

Publication

10/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités