Known Vulnerabilities for Woocommerce by Automattic
Listed below are 3 of the newest known vulnerabilities associated with "Woocommerce" by "Automattic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-39671 json | Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-fo... | Not Provided | 2026-04-08 | 2026-04-13 |
| CVE-2026-39668 json | Missing Authorization vulnerability in g5theme Book Previewer for Woocommerce book-previewer-for-woocommerce allows Exploitin... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-39662 json | Missing Authorization vulnerability in ProWCPlugins Product Price by Formula for WooCommerce product-price-by-formula-for-woo... | Not Provided | 2026-04-08 | 2026-04-09 |
| CVE-2026-39656 json | Missing Authorization vulnerability in Razorpay Razorpay for WooCommerce woo-razorpay allows Exploiting Incorrectly Configure... | Not Provided | 2026-04-08 | 2026-04-13 |
| CVE-2026-39645 json | Server-Side Request Forgery (SSRF) vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommerce al... | Not Provided | 2026-04-08 | 2026-04-13 |
| CVE-2026-39643 json | Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce allo... | Not Provided | 2026-04-08 | 2026-04-13 |
| CVE-2026-39542 json | Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocomme... | Not Provided | 2026-04-08 | 2026-04-14 |
| CVE-2026-39508 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Advanced ... | Not Provided | 2026-04-08 | 2026-04-10 |
| CVE-2026-39501 json | Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured ... | Not Provided | 2026-04-08 | 2026-04-10 |
| CVE-2026-39497 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocomme... | Not Provided | 2026-04-08 | 2026-04-10 |