{"schema_version":1,"title":"WooCommerce vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in WooCommerce: 4 in the last 7 days and 14 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-89055, was published on 25 September 2026.","url":"https://junglewise.ai/threats/vendors/woocommerce","json_url":"https://junglewise.ai/threats/vendors/woocommerce.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/woocommerce","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":6,"all_time":19,"critical":3,"exploited":0,"last_7_days":4,"last_30_days":9,"last_90_days":14,"last_365_days":19},"latest":[{"cve":"CVE-2026-89055","cvss":9.1,"epss":0.0039,"slug":"cve-2026-89055-the-customer-reviews-for-woocommerce-plugin-for-wordpress-is","title":"Customer Reviews for WooCommerce authorization bypass","severity":"critical","exploited":false,"published_at":"2026-09-25T07:16:55.14+00:00","url":"https://junglewise.ai/threats/cve-2026-89055-the-customer-reviews-for-woocommerce-plugin-for-wordpress-is"},{"cve":"CVE-2026-88929","cvss":5.3,"epss":0.0021,"slug":"cve-2026-88929-the-product-badge-label-countdown-timer-for-woocommerce-wordpress","title":"Sale Booster unauthenticated product information disclosure","severity":"medium","exploited":false,"published_at":"2026-09-23T06:17:04.86+00:00","url":"https://junglewise.ai/threats/cve-2026-88929-the-product-badge-label-countdown-timer-for-woocommerce-wordpress"},{"cve":"CVE-2026-92400","cvss":5.3,"epss":0.0016,"slug":"cve-2026-92400-the-payment-gateway-for-paypal-on-woocommerce-wordpress-plugin","title":"Payment Gateway for PayPal on WooCommerce payment verification bypass","severity":"medium","exploited":false,"published_at":"2026-09-21T09:17:06.27+00:00","url":"https://junglewise.ai/threats/cve-2026-92400-the-payment-gateway-for-paypal-on-woocommerce-wordpress-plugin"},{"cve":"CVE-2026-82187","cvss":9.8,"epss":0.0055,"slug":"cve-2026-82187-the-web-to-print-online-designer-wordpress-plugin-before-2-15-0","title":"Web to Print Online Designer arbitrary file upload","severity":"critical","exploited":false,"published_at":"2026-09-21T07:16:53.317+00:00","url":"https://junglewise.ai/threats/cve-2026-82187-the-web-to-print-online-designer-wordpress-plugin-before-2-15-0"},{"cve":"CVE-2026-87831","cvss":4.3,"epss":0.0025,"slug":"cve-2026-87831-checkout-field-manager-for-woocommerce-arbitrary-attachment","title":"Checkout Field Manager for WooCommerce arbitrary attachment deletion","severity":"medium","exploited":false,"published_at":"2026-09-17T08:17:02.493+00:00","url":"https://junglewise.ai/threats/cve-2026-87831-checkout-field-manager-for-woocommerce-arbitrary-attachment"},{"cve":"CVE-2026-87829","cvss":4.3,"epss":0.0025,"slug":"cve-2026-87829-checkout-field-manager-for-woocommerce-attachment-deletion","title":"Checkout Field Manager for WooCommerce attachment deletion without ownership validation","severity":"medium","exploited":false,"published_at":"2026-09-17T08:17:02.363+00:00","url":"https://junglewise.ai/threats/cve-2026-87829-checkout-field-manager-for-woocommerce-attachment-deletion"},{"cve":"CVE-2026-84024","cvss":4.3,"epss":0.0014,"slug":"cve-2026-84024-bear-csrf-in-meta-field-configuration","title":"BEAR CSRF in meta field configuration","severity":"medium","exploited":false,"published_at":"2026-09-12T06:16:26.573+00:00","url":"https://junglewise.ai/threats/cve-2026-84024-bear-csrf-in-meta-field-configuration"},{"cve":"CVE-2026-84760","cvss":5.3,"epss":0.0031,"slug":"cve-2026-84760-ultimate-gift-cards-for-woocommerce-broken-access-control","title":"Ultimate Gift Cards For WooCommerce broken access control","severity":"medium","exploited":false,"published_at":"2026-09-02T12:17:14.66+00:00","url":"https://junglewise.ai/threats/cve-2026-84760-ultimate-gift-cards-for-woocommerce-broken-access-control"},{"cve":"CVE-2026-79621","cvss":4.3,"epss":0.0015,"slug":"cve-2026-79621-catalogx-wordpress-plugin-email-content-injection","title":"CatalogX WordPress plugin email content injection","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:18.39+00:00","url":"https://junglewise.ai/threats/cve-2026-79621-catalogx-wordpress-plugin-email-content-injection"},{"cve":"CVE-2026-18884","cvss":7.5,"epss":0.0032,"slug":"cve-2026-18884-woocommerce-lottery-sql-injection-in-orderby-parameter","title":"WooCommerce Lottery SQL injection in orderby parameter","severity":"high","exploited":false,"published_at":"2026-08-26T08:16:44.66+00:00","url":"https://junglewise.ai/threats/cve-2026-18884-woocommerce-lottery-sql-injection-in-orderby-parameter"},{"cve":"CVE-2026-28171","cvss":8.6,"epss":0.0053,"slug":"cve-2026-28171-woocommerce-file-approval-arbitrary-file-deletion","title":"WooCommerce File Approval arbitrary file deletion","severity":"high","exploited":false,"published_at":"2026-08-24T12:16:50.97+00:00","url":"https://junglewise.ai/threats/cve-2026-28171-woocommerce-file-approval-arbitrary-file-deletion"},{"cve":"CVE-2026-18391","cvss":9.8,"epss":0.0096,"slug":"cve-2026-18391-woocommerce-subscriptions-php-object-injection-to-rce","title":"WooCommerce Subscriptions PHP Object Injection to RCE","severity":"critical","exploited":false,"published_at":"2026-08-12T06:20:14.167+00:00","url":"https://junglewise.ai/threats/cve-2026-18391-woocommerce-subscriptions-php-object-injection-to-rce"},{"cve":"CVE-2026-16285","cvss":7.5,"epss":0.0041,"slug":"cve-2026-16285-product-attachment-for-woocommerce-authorization-bypass-in-media","title":"Product Attachment for WooCommerce authorization bypass in media download","severity":"high","exploited":false,"published_at":"2026-08-02T06:16:40.113+00:00","url":"https://junglewise.ai/threats/cve-2026-16285-product-attachment-for-woocommerce-authorization-bypass-in-media"},{"cve":"CVE-2025-14073","cvss":5.3,"slug":"cve-2025-14073-woocommerce-paypal-payments-idor-in-enqueue-paypal-insights","title":"WooCommerce PayPal Payments IDOR in enqueue_paypal_insights_script_on_order_received","severity":"medium","exploited":false,"published_at":"2026-08-01T09:16:57.24+00:00","url":"https://junglewise.ai/threats/cve-2025-14073-woocommerce-paypal-payments-idor-in-enqueue-paypal-insights"},{"cve":"CVE-2026-2381","cvss":6.5,"slug":"cve-2026-2381-woocommerce-stripe-payment-gateway-unauthorized-order-modification","title":"WooCommerce Stripe Payment Gateway unauthorized order modification","severity":"medium","exploited":false,"published_at":"2026-06-16T10:16:26.827+00:00","url":"https://junglewise.ai/threats/cve-2026-2381-woocommerce-stripe-payment-gateway-unauthorized-order-modification"},{"cve":"CVE-2026-9662","cvss":8.1,"slug":"cve-2026-9662-woocommerce-recover-exit-local-file-inclusion-in-recover-exit","title":"WooCommerce Recover Exit local file inclusion in recover_exit","severity":"high","exploited":false,"published_at":"2026-06-09T05:16:41.35+00:00","url":"https://junglewise.ai/threats/cve-2026-9662-woocommerce-recover-exit-local-file-inclusion-in-recover-exit"},{"cve":"CVE-2026-9284","cvss":8.2,"epss":0.0006,"slug":"cve-2026-9284-woocommerce-paypal-payments-missing-authorization-in-ajax","title":"WooCommerce PayPal Payments missing authorization in AJAX endpoints","severity":"high","exploited":false,"published_at":"2026-05-23T05:16:34.98+00:00","url":"https://junglewise.ai/threats/cve-2026-9284-woocommerce-paypal-payments-missing-authorization-in-ajax"},{"cve":"CVE-2018-25325","cvss":7.5,"slug":"cve-2018-25325-woocommerce-csv-importer-path-traversal-in-delete-export-file","title":"WooCommerce CSV Importer path traversal in delete_export_file","severity":"high","exploited":false,"published_at":"2026-05-17T13:16:43.923+00:00","url":"https://junglewise.ai/threats/cve-2018-25325-woocommerce-csv-importer-path-traversal-in-delete-export-file"},{"cve":"CVE-2026-6932","cvss":4.3,"slug":"cve-2026-6932-woo-commerce-minimum-weight-csrf-in-edit-weight-php","title":"Woo Commerce Minimum Weight CSRF in edit-weight.php","severity":"medium","exploited":false,"published_at":"2026-05-12T09:16:56.77+00:00","url":"https://junglewise.ai/threats/cve-2026-6932-woo-commerce-minimum-weight-csrf-in-edit-weight-php"}],"vendor":{"hub":true,"name":"WooCommerce","slug":"woocommerce","homepage":"https://woocommerce.com/","description":"An open-source e-commerce platform built for WordPress.","url":"https://junglewise.ai/threats/vendors/woocommerce"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":2,"exploited":0,"vulnerabilities":4}],"most_severe":[{"cve":"CVE-2026-18391","cvss":9.8,"epss":0.0096,"slug":"cve-2026-18391-woocommerce-subscriptions-php-object-injection-to-rce","title":"WooCommerce Subscriptions PHP Object Injection to RCE","severity":"critical","exploited":false,"published_at":"2026-08-12T06:20:14.167+00:00","url":"https://junglewise.ai/threats/cve-2026-18391-woocommerce-subscriptions-php-object-injection-to-rce"},{"cve":"CVE-2026-82187","cvss":9.8,"epss":0.0055,"slug":"cve-2026-82187-the-web-to-print-online-designer-wordpress-plugin-before-2-15-0","title":"Web to Print Online Designer arbitrary file upload","severity":"critical","exploited":false,"published_at":"2026-09-21T07:16:53.317+00:00","url":"https://junglewise.ai/threats/cve-2026-82187-the-web-to-print-online-designer-wordpress-plugin-before-2-15-0"},{"cve":"CVE-2026-89055","cvss":9.1,"epss":0.0039,"slug":"cve-2026-89055-the-customer-reviews-for-woocommerce-plugin-for-wordpress-is","title":"Customer Reviews for WooCommerce authorization bypass","severity":"critical","exploited":false,"published_at":"2026-09-25T07:16:55.14+00:00","url":"https://junglewise.ai/threats/cve-2026-89055-the-customer-reviews-for-woocommerce-plugin-for-wordpress-is"},{"cve":"CVE-2026-28171","cvss":8.6,"epss":0.0053,"slug":"cve-2026-28171-woocommerce-file-approval-arbitrary-file-deletion","title":"WooCommerce File Approval arbitrary file deletion","severity":"high","exploited":false,"published_at":"2026-08-24T12:16:50.97+00:00","url":"https://junglewise.ai/threats/cve-2026-28171-woocommerce-file-approval-arbitrary-file-deletion"},{"cve":"CVE-2026-9284","cvss":8.2,"epss":0.0006,"slug":"cve-2026-9284-woocommerce-paypal-payments-missing-authorization-in-ajax","title":"WooCommerce PayPal Payments missing authorization in AJAX endpoints","severity":"high","exploited":false,"published_at":"2026-05-23T05:16:34.98+00:00","url":"https://junglewise.ai/threats/cve-2026-9284-woocommerce-paypal-payments-missing-authorization-in-ajax"},{"cve":"CVE-2026-9662","cvss":8.1,"slug":"cve-2026-9662-woocommerce-recover-exit-local-file-inclusion-in-recover-exit","title":"WooCommerce Recover Exit local file inclusion in recover_exit","severity":"high","exploited":false,"published_at":"2026-06-09T05:16:41.35+00:00","url":"https://junglewise.ai/threats/cve-2026-9662-woocommerce-recover-exit-local-file-inclusion-in-recover-exit"},{"cve":"CVE-2026-16285","cvss":7.5,"epss":0.0041,"slug":"cve-2026-16285-product-attachment-for-woocommerce-authorization-bypass-in-media","title":"Product Attachment for WooCommerce authorization bypass in media download","severity":"high","exploited":false,"published_at":"2026-08-02T06:16:40.113+00:00","url":"https://junglewise.ai/threats/cve-2026-16285-product-attachment-for-woocommerce-authorization-bypass-in-media"},{"cve":"CVE-2026-18884","cvss":7.5,"epss":0.0032,"slug":"cve-2026-18884-woocommerce-lottery-sql-injection-in-orderby-parameter","title":"WooCommerce Lottery SQL injection in orderby parameter","severity":"high","exploited":false,"published_at":"2026-08-26T08:16:44.66+00:00","url":"https://junglewise.ai/threats/cve-2026-18884-woocommerce-lottery-sql-injection-in-orderby-parameter"},{"cve":"CVE-2018-25325","cvss":7.5,"slug":"cve-2018-25325-woocommerce-csv-importer-path-traversal-in-delete-export-file","title":"WooCommerce CSV Importer path traversal in delete_export_file","severity":"high","exploited":false,"published_at":"2026-05-17T13:16:43.923+00:00","url":"https://junglewise.ai/threats/cve-2018-25325-woocommerce-csv-importer-path-traversal-in-delete-export-file"},{"cve":"CVE-2026-2381","cvss":6.5,"slug":"cve-2026-2381-woocommerce-stripe-payment-gateway-unauthorized-order-modification","title":"WooCommerce Stripe Payment Gateway unauthorized order modification","severity":"medium","exploited":false,"published_at":"2026-06-16T10:16:26.827+00:00","url":"https://junglewise.ai/threats/cve-2026-2381-woocommerce-stripe-payment-gateway-unauthorized-order-modification"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[]}