Skip to content
Threat Feed

Vendor

WooCommerce

9 briefs RSS
high advisory

CVE-2026-8761: Privilege Escalation in Dokan WordPress Plugin

An improper authorization flaw in the Dokan plugin for WordPress allows authenticated attackers with vendor-level access to escalate privileges to administrator via manipulation of the REST API.

Dokan
1r 1t 1c
critical advisory

Critical Arbitrary File Upload in WordPress Extra Checkout Options Plugin Leads to RCE (CVE-2026-14270)

A critical arbitrary file upload vulnerability (CVE-2026-14270) in the Extra Checkout Options plugin for WordPress, affecting versions up to and including 2.3.2, allows low-privileged authenticated users to modify upload allowlists and upload malicious PHP files via an AJAX action, ultimately achieving remote code execution on the server.

Extra Checkout Options wordpress plugin arbitrary-file-upload rce web-application
2r 4t 1c
high advisory

CVE-2026-3688: WordPress WCFM Membership Plugin Insecure Direct Object Reference

Authenticated attackers with vendor-level access can exploit an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-3688) in the WCFM Membership - WooCommerce Memberships for Multivendor Marketplace plugin for WordPress to change any user's role to 'wcfm_vendor' by manipulating membership plans, leading to unauthorized privilege escalation.

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace < 2.11.10 wordpress web vulnerability idor privilege-escalation
2t 1c
high advisory

WooCommerce Infinite Scroll Plugin Vulnerable to PHP Object Injection (CVE-2025-11993)

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection (CVE-2025-11993) due to deserialization of untrusted data in the 'import_settings' function, potentially leading to arbitrary code execution if a suitable POP chain is present.

WooCommerce Infinite Scroll and Ajax Pagination <= 1.8 php-object-injection wordpress woocommerce cve-2025-11993
2r 1t 1c
high advisory

WooCommerce PayPal Payments Plugin Vulnerable to Order Manipulation and Information Disclosure (CVE-2026-9284)

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on WC-AJAX endpoints, allowing attackers to manipulate order payment flows and exfiltrate sensitive order details (CVE-2026-9284).

WooCommerce PayPal Payments plugin <= 4.0.1 woocommerce wordpress paypal authorization-bypass information-disclosure
2r 1t 1c
high threat

Funnel Builder for WooCommerce Checkout Missing Authorization Vulnerability (CVE-2026-47100)

Funnel Builder for WooCommerce Checkout versions prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and inject malicious JavaScript, impacting checkout page visitors.

Funnel Builder for WooCommerce Checkout < 3.15.0.3 cve woocommerce wordpress missing-authorization javascript-injection
2r 1c
high advisory

WooCommerce CSV Importer Path Traversal File Deletion (CVE-2018-25325)

WooCommerce CSV Importer 3.3.6 contains a path traversal vulnerability (CVE-2018-25325) that allows registered users to delete arbitrary files by submitting crafted filenames via the delete_export_file AJAX action.

CSV Importer 3.3.6 path-traversal file-deletion wordpress
2r 1t 1c
medium advisory

CVE-2026-4094: FOX – Currency Switcher Professional for WooCommerce Plugin Vulnerability

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss (CVE-2026-4094) due to a missing capability check, allowing authenticated attackers with Contributor-level access or higher to delete the multi-currency configuration.

FOX – Currency Switcher Professional for WooCommerce plugin <= 1.4.5 wordpress woocommerce plugin csrf data-loss cve-2026-4094
2r 1t 1c
critical advisory

Woocommerce Custom Product Addons Pro Plugin RCE Vulnerability (CVE-2026-4001)

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution (RCE) due to insufficient sanitization of user-submitted field values, allowing unauthenticated attackers to execute arbitrary code via crafted WCPA text fields.

Custom Product Addons Pro plugin wordpress woocommerce rce code-injection cve-2026-4001
2r 1t