Pricing
WordPress securityInstantly fix and mitigate vulnerabilitiesPlugin auditingPaid auditing for WordPress vendorsManaged VDPStart a security program for your pluginsBug BountyJoin the community and earn bountiesEnterprise APIAt scale monitoring and vPatching for hostsVulnerability databaseThe latest WordPress security intelligence
Login Start trial
Plugin Icon

Customer Reviews for WooCommerce

CusRev

Developer

5.90.0

Latest version

80,000

Installations

15 hours ago

Last updated

WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
    Vulnerabilities

Vulnerability history

0 present
14 fixed
10 Mitigation rules
  • Unauthenticated Stored Cross-Site Scripting via `author` Parameter vulnerability
    <= 5.80.2
    Jul 30, 2025
  • Missing Authorization to Authenticated (Subscriber+) Import Cancellation vulnerability
    <= 5.61.0
    Nov 18, 2024
  • Reflected Cross-Site Scripting via 's' vulnerability
    <= 5.47.0
    Apr 19, 2024
  • Missing Authorization to Authenticated (Subscriber+) Coupon Search vulnerability
    <= 5.46.0
    Apr 17, 2024
  • Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending vulnerability
    <= 5.46.0
    Apr 16, 2024
  • Improper Authorization via submit_review vulnerability
    <= 5.38.12
    Feb 7, 2024
  • Authenticated Arbitrary File Upload vulnerability
    <= 5.38.9
    Jan 9, 2024
  • Broken Access Control vulnerability
    <= 5.38.1
    Dec 27, 2023
  • Broken Access Control vulnerability
    <= 5.36.0
    Oct 6, 2023
  • Contributor+ Stored XSS vulnerability
    < 5.17.0
    Jan 24, 2023
  • Contributor+ LFI vulnerability
    < 5.16.0
    Jan 23, 2023
  • Authenticated Broken Access Control vulnerability
    <= 5.3.5
    Sep 22, 2022
  • Cross-Site Request Forgery (CSRF) vulnerability
    <= 5.3.5
    Sep 22, 2022
  • Sensitive Information Disclosure vulnerability
    <= 5.3.5
    Sep 22, 2022

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • Documentation
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory 1064
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag