Known Vulnerabilities for Woocommerce by Automattic
Listed below are 2 of the newest known vulnerabilities associated with "Woocommerce" by "Automattic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-32586 | Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Con... | Not Provided | 2026-03-17 | 2026-04-01 |
| CVE-2026-32526 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Abandoned Ca... | Not Provided | 2026-03-25 | 2026-03-25 |
| CVE-2026-32522 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support ... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-32441 | Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploitin... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-31921 | Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce a... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-31920 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Pro... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-27066 | Missing Authorization vulnerability in PI Web Solution Live sales notification for WooCommerce live-sales-notifications-for-w... | Not Provided | 2026-02-19 | 2026-04-01 |
| CVE-2026-27052 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in vill... | Not Provided | 2026-02-19 | 2026-04-01 |
| CVE-2026-27045 | Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-25469 | Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploit... | Not Provided | 2026-03-25 | 2026-03-26 |