Woocommerce vendor intelligence
Woocommerce Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Woocommerce products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 6
- Known exploited vulnerabilities affecting Woocommerce products
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 6
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 1
- Woocommerce KEV with sensor-observed exploitation activity
The catalog gap matters for Woocommerce exposure
Six of the six exploited Woocommerce vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
- 6
- Product families
Attested Woocommerce vulnerabilities
6 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-0948
Order Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi |
Order Listener for WooCommerce | High | Beyond CISA | 26 May 2026 |
|
CVE-2022-3481
WooCommerce Dropshipping < 4.4 - Unauthenticated SQLi |
WooCommerce Dropshipping | High | Beyond CISA | 12 Feb 2026 |
|
CVE-2021-24212
WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE |
WooCommerce Help Scout | Confirmed | Beyond CISA | 30 Nov 2025 |
|
CVE-2022-4328
WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload |
Checkout Field Manager | High | Beyond CISA | 09 Nov 2025 |
|
CVE-2023-28121
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of... |
WooCommerce Payments | High | Beyond CISA | 17 Jul 2023 |
|
CVE-2021-32790
Blind SQL Injection possible via Authenticated Web-hook Search API Endpoint |
woocommerce | High | Beyond CISA | 26 Jul 2021 |
No Woocommerce vulnerabilities match this search or filter.
Showing 6 of 6 Woocommerce known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, unrestricted upload, and authentication account for six mapped occurrences across this Woocommerce KEV portfolio.