Known Vulnerabilities for WooCommerce by Automattic
Listed below are 4 of the newest known vulnerabilities associated with "WooCommerce" by "Automattic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66711 json | Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-66707 json | Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-66692 json | Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 v... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-66475 json | Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-65559 json | Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-65557 json | Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-65532 json | Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65501 json | Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65457 json | Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65456 json | Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions. | Not Provided | 2026-07-23 | 2026-07-23 |