Vulnerabilities
411 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76201 | Stored XSS in Adobe Commerce and Magento Open Source lets attackers hijack sessions Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected by a stored cross-site scripting flaw (CWE-79) in which an attacker submits crafted content into a vulnerable form field and the malicious JavaScript later executes in any user's browser when they view the page containing that field. The attack vector requires no authentication (network vector, low complexity), but does require user interaction, and the changed scope means injected script can act beyond the vulnerable page, potentially giving the attacker elevated access or control over the victim's account or session. Any organization running an affected version of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source is exposed, especially storefronts that allow unauthenticated form submissions and admin panels reached by privileged users. Exploitation status: no public proof-of-concept is known, the flaw is not listed in CISA KEV, and EPSS estimates only a 0.8% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is documented yet. Do: Apply the patched release referenced in Adobe's security bulletin for CVE-2026-76201 across all Adobe Commerce, Adobe Commerce B2B, and Magento Open Source deployments (exact patched versions are listed in the bulletin). Until patching, review content stored in storefront and admin form fields for unexpected scripts, and restrict/review admin access since stored XSS payloads may already be persisted. If compromise is suspected, rotate credentials for privileged accounts, as changed scope means admin sessions can be hijacked. | 9.3 | <1% |
| largeon the order of 100,000+ live storefronts worldwide | ||
| CVE-2026-76200 | Stored XSS in Adobe Commerce (Magento) Can Hijack Admin and Customer Sessions CVE-2026-76200 is a stored Cross-Site Scripting (CWE-79) flaw in Adobe Commerce that lets an attacker persist malicious JavaScript in vulnerable form fields. When a victim later browses to a page containing the injected field, the script executes in their browser with the CVSS scope-change (S:C) indicating the impact crosses component boundaries, such as reaching an admin or another user's session. An attacker who succeeds can gain elevated access or control over the victim's account or session, which on an e-commerce platform could mean admin panel access or compromise of customer accounts. Affected products are Adobe Commerce, Magento, and the Commerce B2B offering, with specific affected and fixed version ranges not stated in the available data. Exploitation has not been confirmed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.8% chance of exploitation within 30 days. Do: Patch by upgrading to the release specified in Adobe's security bulletin for this CVE, prioritizing stores with internet-exposed account or checkout forms where the vulnerable fields can be populated. Until patched, restrict and sanitize input to the affected form fields and review recent admin/customer session activity for signs of hijacking. Because scope is 'changed', assume a successful injection could compromise higher-privileged sessions than the field's own context, so validate any admin accounts that interacted with attacker-modified content. | 9.3 | <1% |
| largeorder of tens of thousands of live stores (≈50,000–150,000 Magento/Adobe Commerce deployments) | ||
| CVE-2026-81792 | Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions. Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-81790 | Missing Authorization in Csomagpontok és szállítási címkék WooCommerce-hez plugin CVE-2026-81790 is a missing-authorization flaw (CWE-862) in the WordPress/WooCommerce plugin "Csomagpontok és szállítási címkék WooCommerce-hez" (pickup points and shipping labels) by Viszt Péter, where incorrectly configured access controls allow requests to bypass required permission checks. Because the check is absent for unauthenticated users (CVSS AV:N/PR:N), a remote attacker with no account can invoke the affected plugin functionality over the network. Per the CVSS 3.1 vector, the attacker gains high integrity impact (ability to modify data or settings) with no confidentiality or availability impact. All plugin versions before 4.2.8 are affected, so any WooCommerce shop running an older version is exposed. There is currently no known public PoC, no CISA KEV listing, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days (18th percentile), so exploitation is not known to be occurring. Do: Update the plugin to version 4.2.8 or later as soon as possible. If immediate patching is not possible, restrict unauthenticated access to the plugin's endpoints (e.g., via WAF rules) and review pickup-point/shipping-label settings and related data for unauthorized changes. No public PoC or in-the-wild exploitation is known, but remediation is straightforward and should be prioritized given the flaw is remotely exploitable without credentials. | 7.5 | <1% |
| moderate≈10,000+ WooCommerce sites (est.; regional Hungarian-market plugin) | ||
| CVE-2026-48888 | Unauthenticated resource-exhaustion DoS in WooCommerce before 11.1.0 WooCommerce, the e-commerce plugin for WordPress from Automattic, contains an 'Allocation of Resources Without Limits or Throttling' flaw (CWE-770) that allows HTTP denial of service. An unauthenticated remote attacker can trigger it over the network with low complexity by sending requests that cause the plugin to allocate resources without any cap or rate limiting, exhausting server capacity. The impact is availability-only: an attacker can degrade or take down the affected storefront but gains no confidentiality or integrity impact. Any WooCommerce deployment running a version before 11.1.0 is affected. Exploitation has not been observed: there is no known public proof-of-concept, the CVE is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days. Do: Upgrade WooCommerce to version 11.1.0 or later, which resolves this issue. Until patched, check your installed WooCommerce version in the WordPress plugins list and consider WAF or reverse-proxy rate limiting on the store's public endpoints to blunt unauthenticated request floods. There is no evidence of active exploitation, so patching at normal priority is reasonable, though high-availability storefronts should patch sooner. | 7.5 | <1% |
| mass≈5,000,000+ WordPress sites (WooCommerce active-install count on WordPress.org), most plausibly running pre-11.1.0 releases | ||
| CVE-2026-75650 | Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650) Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08. Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line. | 10.0 | 2% | KEV PoC |
| massroughly 100,000-300,000 internet-facing storefronts | |
| CVE-2026-84186 | Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via th Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse proxy, load balancer or CDN. The application incorrectly processes the IP address string and uses the address controlled by the visitor rather than the one provided by the trusted infrastructure, allowing an unauthenticated remote attacker to cause the application to interpret their connection as originating from an arbitrary IP address. This condition allows IP-based controls, such as the maintenance mode allowlist, to be bypassed, as well as enabling the forgery of security and audit logs and the evasion of third-party mechanisms that rely on the IP address, such as geolocation checks, fraud detection or request throttling. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2026-85038 | The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a rol The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-10196 | Unauthenticated PHP Object Injection to RCE in WordPress Mail Mint Plugin The Mail Mint WordPress plugin (email marketing, newsletter, and automation) deserializes untrusted input in its 'handle_form_submission' function without adequate validation, enabling unauthenticated attackers to inject a PHP object. Because the form-submission handler requires no authentication or privileges, any visitor able to reach a Mail Mint form can trigger the flaw. By supplying a crafted serialized object, an attacker can exploit an available POP chain to execute code on the server, potentially leading to full site compromise (CVSS 9.8). All versions through 1.31.0 are affected; the fix in 1.23.1 was only partial, so sites running even partially patched releases remain exposed. No public proof-of-concept exists, the flaw is not in CISA's KEV, and EPSS assigns a 0.6% probability of exploitation within 30 days, indicating no confirmed in-the-wild exploitation yet. Do: Update Mail Mint to the first available release after 1.31.0, since 1.23.1 was only a partial fix and should not be relied upon. Until a fully patched release is applied, deactivate the plugin or restrict access to its form submission endpoints, and consider WAF rules blocking serialized-object (O:) patterns in form POSTs. No public PoC is known, but the flaw is unauthenticated and trivially triggerable wherever forms are exposed, so treat patching as high priority. | 9.8 | <1% |
| largeon the order of 100,000 WordPress sites (estimate) | ||
| CVE-2026-81543 | Authenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce (<= 10.7.1) CVE-2026-81543 is a privilege-escalation flaw in the Abandoned Cart Pro for WooCommerce WordPress plugin: several of its AJAX actions (wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data) lack capability checks and nonce verification. Any logged-in user with subscriber-level access or above can therefore invoke these actions, for example rewriting the plugin's SMTP connector settings so that the store's administrator recovery emails are routed through an attacker-controlled mail server. With the plugin's auto-login feature enabled (its default configuration), the attacker can then trigger a recovery email, capture the auto-login link it contains, and use it to obtain full administrator access to the site. Any WordPress site running the plugin in versions up to and including 10.7.1 is affected, provided it has at least one subscriber-level account, which is effectively every WooCommerce store with customer registration. No public proof-of-concept or confirmed in-the-wild exploitation is known, and EPSS currently assigns roughly a 0.2% probability of exploitation within 30 days. Do: Update Abandoned Cart Pro for WooCommerce to a release newer than 10.7.1 on every store where the plugin is active. Until patched, disable the plugin's auto-login feature, restrict or vet subscriber registrations, and verify that the SMTP connector settings have not been altered. Also review recent administrator password-reset/recovery emails and admin logins for signs that auto-login links were intercepted. | 8.8 | <1% |
| largeroughly 10,000-30,000 WooCommerce sites (premium plugin, no public install count) | ||
| CVE-2026-75018 | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently force-delete arbitrary posts of any post type (including pages, administrator-authored posts, and WooCommerce products) and write arbitrary ccf_field_* post meta onto any post regardless of ownership or post type. The top-level form ID is checked via edit_post/publish_posts, but the nested fields[].ID and choices[].ID paths processed by _create_and_map_fields() and _create_and_map_choices() carry no equivalent capability or post-type guard, leaving those sinks fully exposed while delete_item() and delete_submission() contain explicit post-type restriction fixes demonstrating the developer's awareness of scoping requirements. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2026-84045 | The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the serve The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary price. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-84043 | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing un The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-57777 | Blind SQL Injection in Automattic WooCommerce (WordPress) CVE-2026-57777 is a blind SQL injection flaw in WooCommerce, Automattic's e-commerce plugin for WordPress, caused by improper neutralization of special elements used in an SQL command (CWE-89). The vulnerability is network-reachable but requires the attacker to already hold a high-privilege account (CVSS privileges required: high), meaning privileged user input is passed into a SQL query without adequate sanitization. Successful exploitation enables blind extraction of database contents, with CVSS rating the confidentiality impact as high (and availability impact low), potentially exposing store, customer, and order data. Any WordPress site running WooCommerce in any version before 11.0 is affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so no in-the-wild exploitation is known. Do: Update WooCommerce to 11.0 or later as soon as possible. Because exploitation requires a high-privilege account, audit administrator and shop-manager accounts, remove unnecessary privileged users, and review their recent activity for signs of data exfiltration; WAF rules that block common blind SQL injection patterns can serve as a temporary mitigation. | 7.6 | <1% |
| massmillions of WordPress sites (WooCommerce reports ~5M+ active installs; only stores still running versions below 11.0 are vulnerable) | ||
| CVE-2026-84146 | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce p The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status). NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-84849 | Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-84238 | Unauthenticated Broken Access Control in YITH Request a Quote Premium YITH Request a Quote for WooCommerce Premium, in versions before 4.46.0, contains an unauthenticated broken access control flaw classified as CWE-862 (Missing Authorization), meaning functionality that should verify a user's permissions performs no authorization check at all. Because no credentials are required, any remote attacker can trigger the affected functionality directly over the network with no user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). The critical 9.8 rating, with high impact to confidentiality, integrity, and availability, indicates an attacker can access protected functionality and data as if authorized, exposing or manipulating sensitive quote and store information. All deployments of the Premium edition prior to 4.46.0 are affected; the free edition is not named in the advisory. There is currently no public proof of concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at just 0.3% (19th percentile), so no in-the-wild exploitation is documented. Do: Upgrade YITH Request a Quote for WooCommerce Premium to version 4.46.0 or later, and confirm the installed version on the WordPress plugins screen. Since the flaw is exploitable without credentials and no public PoC exists, a WAF rule restricting unauthenticated access to the plugin's endpoints is a reasonable interim measure while patching. No other mitigations are documented in the available advisory data. | 9.8 | <1% |
| moderatelikely roughly 1,000-10,000 premium sites (free edition lists ~20,000+ active installs; premium is a paid subset) | ||
| CVE-2026-81282 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-84760 | Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-81774 | Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment CVE-2026-81774 is an unauthenticated sensitive data exposure flaw (CWE-497, exposure of sensitive information to an unauthorized control sphere) in the WooCommerce Product Attachment plugin for WordPress, affecting all versions up to and including 2.3.3 and scored 7.5 (High) with a fully network-based, low-complexity attack vector. An unauthenticated remote attacker can trigger it by sending ordinary HTTP requests to the plugin's exposed functionality, with no login, privileges, or user interaction required. The attacker gains read access to sensitive data handled or exposed by the plugin or host site (high confidentiality impact only; no integrity or availability impact per the CVSS score). Affected parties are WordPress e-commerce sites running WooCommerce with WooCommerce Product Attachment installed at version 2.3.3 or earlier. As of this advisory the flaw is not known to be exploited: EPSS is 0.3% (23rd percentile), it is not in CISA's KEV, and no public proof-of-concept exists. Do: Update WooCommerce Product Attachment to the latest vendor release (any version newer than 2.3.3) as soon as one is available. Until patched, restrict access to plugin-managed attachment files and endpoints, review web logs for unauthenticated requests to them, and assume any sensitive documents served through the plugin may have been quietly read. | 7.5 | <1% |
| moderatelikely on the order of thousands of sites (estimated; no authoritative active-install count available) | ||
| CVE-2026-81288 | Unauthenticated XSS in Upsell Order Bump Offer for WooCommerce (<= 3.1.5) CVE-2026-81288 is an unauthenticated cross-site scripting (XSS, CWE-79) flaw in the Upsell Order Bump Offer for WooCommerce WordPress plugin, affecting all versions up to and including 3.1.5. Because no authentication is required, an unauthenticated attacker can inject malicious script that executes when a victim — per the CVSS user-interaction requirement, most plausibly a store admin or shopper — views a crafted link, request, or page; the CVSS scope-change flag indicates the injected script can act beyond the vulnerable component's normal trust boundary. A successful attack lets the attacker run arbitrary JavaScript in the victim's browser on the WooCommerce store, enabling actions such as stealing session cookies or performing unintended actions in the victim's context. Any WordPress/WooCommerce site running the plugin at version 3.1.5 or older is affected. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days. Do: Update the plugin to the latest release (any version after 3.1.5; confirm the exact fixed version in the vendor changelog). Until patched, administrators should review recently changed or added admin accounts and check checkout/upsell pages for unexpected scripts or injected content, since an unauthenticated XSS can target admin browsers. Monitor the plugin page for the patched release and consider web-application-filter rules on plugin endpoints. | 7.1 | <1% |
| largeon the order of 10,000–30,000 WooCommerce sites running the plugin | ||
| CVE-2026-84438 | A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete Workflow. This manipulation of the argument firstname causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.0 | <1% |
| — | ||
| CVE-2026-84437 | A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manipulation of the argument address_1 results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.0 | <1% |
| — | ||
| CVE-2026-19948 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass i The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve the name, price, short description, image URL, permalink, stock status, and product type of draft, pending, private, and catalog-hidden WooCommerce products not intended to be publicly visible. The sidebarNonce value is emitted unconditionally into public page HTML by multiple block renderers with no login gate, allowing unauthenticated visitors to harvest a valid nonce and pass the only authentication check in the handler. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-81280 | Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-76585 | Unauthenticated Stored XSS in Customer Reviews for WooCommerce WordPress Plugin The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 fails to sanitise and escape the content of customer reviews submitted through one of its endpoints. An unauthenticated attacker can submit a review containing malicious HTML/JavaScript, which is then stored and executed in the browser of anyone who views the review content, such as an administrator moderating reviews or a customer browsing the shop. By running attacker-controlled JavaScript in an admin's or visitor's browser, the attacker can perform actions in that user's session, such as creating backdoor admin users, altering pages, or redirecting visitors. Any WooCommerce store running the plugin in a version below 5.118.0 is affected. There is currently no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, so no in-the-wild exploitation is known. Do: Update the plugin to version 5.118.0 or later. Until patched, restrict or disable unauthenticated review submission through the affected endpoint and moderate incoming reviews manually; after patching, review stored customer reviews for injected HTML/script tags and watch for unexpected admin users or modified site content that could indicate exploitation. | 8.8 | <1% |
| moderate≈30,000+ active installs of the plugin (order of tens of thousands of WooCommerce sites) | ||
| CVE-2026-15369 | Unauthenticated Privilege Escalation in Custom User Registration Fields for WooCommerce Custom User Registration Fields for WooCommerce, a WordPress plugin used with WooCommerce stores, contains a critical unauthenticated privilege escalation flaw in versions up to and including 2.2.3. The plugin accepts an attacker-controlled 'afreg_select_user_role' value from the unauthenticated WooCommerce Store API checkout request (/wc/store/v1/checkout), persists it in order meta, and later passes it directly to WP_User::add_role() during order processing on the woocommerce_thankyou hook without validating it against the admin-configured allowed role list. An unauthenticated attacker who creates an account during checkout can modify the JSON body to request the administrator role (or any other role slug) and gain full administrative control of the site. Only sites running version 2.2.3 or earlier with the plugin's 'User Role Selection' setting enabled are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS estimates only a 0.4% probability of exploitation within 30 days. Do: Update the plugin to a version newer than 2.2.3 as soon as a patched release is published (no fixed version number was provided in the source data), and verify the installed version on the WordPress Plugins page. As an interim mitigation, disable the plugin's 'User Role Selection' setting so checkout role data is not applied to newly created accounts. Also audit recently created user accounts for unexpected Administrator role grants, since successful exploitation adds the attacker-specified role. | 9.8 | <1% |
| largeplausibly on the order of tens of thousands of WooCommerce sites; only the subset with the 'User Role Selection' setting enabled is actually exploitable | ||
| CVE-2026-16947 | Unauthenticated SSRF in Total Processing Card Payments for WooCommerce plugin CVE-2026-16947 is an unauthenticated server-side request forgery (CWE-918) combined with missing response-authenticity verification in the Total Processing Card Payments for WooCommerce WordPress plugin, affecting all versions through 7.3. The plugin builds a server-side payment verification request from a user-supplied path without validating it, and does not verify that the response it receives genuinely comes from the payment gateway. An unauthenticated attacker can redirect that request to an arbitrary attacker-controlled host, causing the merchant's payment-gateway credentials to be disclosed, and can return a forged success response that marks arbitrary WooCommerce orders as paid without actual payment. Any WordPress/WooCommerce store running the affected versions is exposed, with no authentication or user interaction required. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates only a 0.2% probability of exploitation within 30 days. Do: Upgrade the plugin to a release newer than 7.3 as soon as the vendor publishes a fix (no fixed version number is available in the source data). Until patched, audit recent WooCommerce orders for transactions marked paid without a matching gateway payment, and treat stored Total Processing API credentials as potentially exposed, rotating them if compromise is suspected; a WAF rule restricting unauthenticated requests to the plugin's verification endpoint may reduce exposure. | 9.1 | <1% |
| nichelikely hundreds to low thousands of WooCommerce stores (estimated; no install count provided in the data) | ||
| CVE-2026-6176 | Unauthenticated Stored XSS in Customer Reviews for WooCommerce WordPress plugin CVE-2026-6176 is a stored cross-site scripting (CWE-79) vulnerability in the Customer Reviews for WooCommerce WordPress plugin, present in all versions up to and including 5.106.0, caused by insufficient input sanitization and output escaping of user-supplied review comment text. An unauthenticated attacker who has a valid review form URL - normally a customer who received one of the plugin's review reminder emails after placing an order - can submit a crafted review through the 'cr_local_forms_submit' AJAX action, and the plugin stores the unsanitized HTML in a comment via wp_insert_comment(). When that review is later rendered on a product page through comment_text(), the injected script executes in the browser of anyone who views the page, letting the attacker run arbitrary JavaScript to steal session data, redirect shoppers, or alter page content. Any WooCommerce store running the plugin at version 5.106.0 or earlier is affected - especially stores that send aggregated review invitation emails - and the flaw is rated High severity (CVSS 3.1: 7.2) with confidentiality and integrity impact but no availability impact. No public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.3% chance of exploitation within 30 days) indicate that exploitation has not yet been observed. Do: Update Customer Reviews for WooCommerce to a release later than 5.106.0 (the patched version published by the developer) on all WooCommerce stores, prioritizing shops that use review reminder emails. As an interim mitigation, disable or restrict the aggregated review form and its reminder-email links, and audit existing review comments for embedded HTML or script tags. Because no public proof-of-concept or in-the-wild exploitation is known, this can be handled on a normal patch cycle while monitoring for the fixed release. | 7.2 | <1% |
| largetens of thousands of WordPress sites (roughly 30,000-50,000 active installs) | ||
| CVE-2026-38725 | xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in aj xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and rendered in Smarty templates without output escaping, resulting in Stored Cross-Site Scripting (XSS). When an administrator reviews comments in the back office, the payload executes with admin-level session context, leading to full store compromise. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2026-14942 | Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugin and was never published. Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugin and was never published. The report was withdrawn: the precondition it depends on, an attacker obtaining a review form identifier belonging to a customer they do not already have access to, could not be demonstrated. No advisory was issued for this ID. NVD description · AI analysis pending | — | — |
| — | ||
| CVE-2026-81277 | Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. NVD description · AI analysis pending | 8.5 | <1% |
| — | ||
| CVE-2026-78283 | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. NVD description · AI analysis pending | 7.1 | <1% |
| — | ||
| CVE-2026-27330 | Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. NVD description · AI analysis pending | 8.6 | <1% |
| — | ||
| CVE-2026-16568 +1 in the same advisory: …16569 | The Mobile App for WooCommerce: The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2026-18080 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, an The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing file extension validation and missing path normalization when CRM Email Connect processes inbound IMAP email attachments. This makes it possible for unauthenticated attackers to send a crafted email to the site's configured inbound mailbox with a forged References header matching the plugin's expected pattern and an attachment filename such as `../helper.php`, causing the cron-based IMAP sync job to write attacker-controlled PHP outside of the .htaccess-protected `crm-attachments` directory and into `wp-content/uploads/`. On configurations where PHP executes in uploads, this can lead to remote code execution. Exploitation requires the CRM module and IMAP Email Connect feature to be enabled and configured. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-18884 | The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and inclu The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2026-77695 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return requests on any guest order. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-77693 | The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which pat The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over. NVD description · AI analysis pending | 8.7 | <1% |
| — | ||
| CVE-2026-75971 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core `import_start` action hook with no plugin-owned capability check and no allowlist filtering, causing arbitrary ` ` name/value pairs parsed from an attacker-supplied WXR import file to be passed directly to `update_option()`. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to write arbitrary WordPress options — most critically setting `users_can_register` to `1` and `default_role` to `administrator` — enabling open self-registration of Administrator accounts and full site takeover. This is exploitable by Shop Manager-level users because WooCommerce grants that role the `import` capability, allowing it to reach the WordPress Importer flow that fires the `import_start` hook on which `rum_importer()` is registered, contrary to the assumption that the hook is restricted to Administrators. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2026-32558 | Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-32477 | Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions. Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions. NVD description · AI analysis pending | 8.6 | <1% |
| — | ||
| CVE-2026-28171 | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. NVD description · AI analysis pending | 8.6 | <1% |
| — | ||
| CVE-2026-77116 | Brave Popup Builder (slug: Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2026-14853 | The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by om The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2026-18027 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all version The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The base64-encoded file contents are embedded into the cached invoice HTML and served directly to the attacker via the plugin's own Print/Download invoice endpoints, which require only a valid nonce and access key. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-2996 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and includin The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2026-77264 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versio The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-16962 | The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, c The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated attacker can cancel or fail arbitrary orders store-wide by enumerating ids (triggering downstream stock-release and notification side-effects). NVD description · AI analysis pending | 5.3 | <1% |
| — |