WooCommerce ikon

WooCommerce

4.5/5
7 000 000+ installationer

Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.

52
Kända sårbarheter
14
Kritiska / höga
2025-12-22
Senaste sårbarhet
7 000 000+
Aktiva installationer

Om WooCommerce

WooCommerce är WordPress mest populära e-handelslösning som gör det möjligt att skapa och driva webbutiker direkt från din WordPress-sajt. Med över 7 miljoner aktiva installationer är det det självklara valet för många företag som vill sälja produkter online.

Säkerhetsprofil

WooCommerce har totalt 48 dokumenterade sårbarheter, vilket kan låta mycket men ska ses i relation till tilläggets enorma popularitet och långa utvecklingshistoria. Fördelningen visar 33 medium-risk sårbarheter, 10 high-risk och 4 critical-risk sårbarheter, samt 1 low-risk.

Praktisk bedömning

Den senaste kända sårbarheten rapporterades i september 2021, vilket tyder på att utvecklarna aktivt arbetar med säkerhetsförbättringar. De flesta sårbarheter i kategorin "medium" utgör begränsad risk för välskötta sajter, medan high- och critical-sårbarheter kräver omedelbar uppmärksamhet när de upptäcks.

Rekommendationer

  • Håll alltid WooCommerce uppdaterat till senaste versionen
  • Använd starka lösenord för alla administratörskonton
  • Installera ett säkerhetstillägg som övervakar misstänkt aktivitet
  • Begränsa åtkomst till wp-admin från okända IP-adresser
  • Säkerhetskopiera regelbundet din butik och kunddata

Regelbundna uppdateringar är det absolut viktigaste skyddet mot säkerhetshot – både för WooCommerce och alla andra tillägg på din sajt.

Använder du WooCommerce?

Kör ett gratis test och se om din hemsida är påverkad av dessa sårbarheter.

Testa din hemsida

Alla kända sårbarheter

Medel CVE-2025-15033

WooCommerce <= 10.4.2 - Authenticated (Subscriber+) Information Exposure

Påverkade versioner: <= 10.0.4

Medel CVE-2025-49042

WooCommerce <= 10.0.2 - Authenticated (Shop manager+) Stored Cross-Site Scripting

Påverkade versioner: <= 10.0.2

Medel CVE-2025-5062

WooCommerce <= 9.4.2 - PostMessage-Based Cross-Site Scripting

Påverkade versioner: <= 9.3.2

Medel CVE-2025-26762

WooCommerce <= 9.7.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting

Påverkade versioner: <= 9.7.0

Hög CVE-2021-24511

CVE-2021-24511: The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated befo...

Påverkade versioner: < 3.3.1.0

The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injec...

Medel CVE-2021-38349

CVE-2021-38349: The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which ...

Påverkade versioner: <= 2.1.1

The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inject arbitrary web scripts, in...

Medel CVE-2021-38341

CVE-2021-38341: The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php fil...

Påverkade versioner: <= 2.0.10

The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php file which allows attackers to inject arbitrary web scri...

Kritisk CVE-2021-34646

CVE-2021-34646: Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token gener...

Påverkade versioner: <= 5.4.3

Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link...

Medel CVE-2021-34664

CVE-2021-34664: The Moova for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the lat parameter in the ~/Checkout/Checkout.php file which allows attackers to inject arbitrary web s...

Påverkade versioner: <= 3.5

The Moova for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the lat parameter in the ~/Checkout/Checkout.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.

Medel CVE-2021-32790

CVE-2021-32790: Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious ...

Påverkade versioner: < 3.3.6

Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to...

Hög CVE-2021-34619

CVE-2021-34619: The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file val...

Påverkade versioner: <= 2.5.7

The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin...

Medel CVE-2021-24300

CVE-2021-24300: The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-S...

Påverkade versioner: < 1.13.22

The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue

Hög CVE-2021-24190

CVE-2021-24190: Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (includin...

Påverkade versioner: < 1.5.2

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository,...

Kritisk CVE-2021-24212

CVE-2021-24212: The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default wil...

Påverkade versioner: < 2.9.1

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

Kritisk CVE-2021-24171

CVE-2021-24171: The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP exten...

Påverkade versioner: < 59.4

The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within anothe...

Medel CVE-2021-24169

CVE-2021-24169: This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

Påverkade versioner: < 3.1.8

This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

Kritisk CVE-2021-3120

CVE-2021-3120: An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system ...

Påverkade versioner: < 3.3.1

An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order t...

Medel CVE-2020-29156

CVE-2020-29156: The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

Påverkade versioner: < 4.7.0

The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

Hög CVE-2020-11497

CVE-2020-11497: An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitr...

Påverkade versioner: all

An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details en...

Medel CVE-2019-18834

CVE-2019-18834: Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Ty...

Påverkade versioner: < 2.6.3

Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.

Medel CVE-2020-11727

CVE-2020-11727: A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the v...

Påverkade versioner: all

A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the view/settings-form.php woe_post_type parameter.

Medel CVE-2014-4558

CVE-2014-4558: Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HT...

Påverkade versioner: <= 2.7.1

Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.

Medel CVE-2019-14979

CVE-2019-14979: cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purc...

Påverkade versioner: all

cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOT...

Medel CVE-2019-14978

CVE-2019-14978: /payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for...

Påverkade versioner: all

/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for lower than the intended price.

Medel CVE-2017-18592

CVE-2017-18592: The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.

Påverkade versioner: < 3.1.0

The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.

Hög CVE-2016-10935

CVE-2016-10935: The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.

Påverkade versioner: < 1.8.4

The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.

Medel CVE-2019-15092

CVE-2019-15092: The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported...

Påverkade versioner: <= 1.3.1

The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporte...

Hög CVE-2016-10923

CVE-2016-10923: The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.

Påverkade versioner: < 1.5.8

The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.

Hög CVE-2016-10922

CVE-2016-10922: The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.

Påverkade versioner: < 1.5.7

The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.

Medel CVE-2018-20966

CVE-2018-20966: The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.

Påverkade versioner: < 3.8.0

The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.

Medel CVE-2019-14948

CVE-2019-14948: The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.

Påverkade versioner: < 18.4

The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.

Medel CVE-2017-18506

CVE-2017-18506: The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.

Påverkade versioner: < 2.0.13

The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.

Medel CVE-2019-14796

CVE-2019-14796: The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_l...

Påverkade versioner: all

The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.

Medel CVE-2019-1010124

CVE-2019-1010124: WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/wo...

Påverkade versioner: <= 2.2.18

WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Admi...

Medel CVE-2019-11807

CVE-2019-11807: The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a no...

Påverkade versioner: < 4.3

The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.

Medel CVE-2019-7441

CVE-2019-7441: cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purch...

Påverkade versioner: all

cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE...

Medel CVE-2018-20714

CVE-2018-20714: The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain pr...

Påverkade versioner: < 3.4.6

The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a sh...

Medel CVE-2017-18356

CVE-2017-18356: In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The att...

Påverkade versioner: < 3.2.4

In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string t...

Medel CVE-2018-11525

CVE-2018-11525: The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.

Påverkade versioner: <= 1.5.4

The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.

Medel CVE-2018-11486

CVE-2018-11486: An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non...

Påverkade versioner: <= 1.0.9

An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and...

Medel CVE-2018-11485

CVE-2018-11485: The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders ad...

Påverkade versioner: <= 1.0.6

The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "re...

Medel CVE-2018-11579

CVE-2018-11579: class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_n...

Påverkade versioner: all

class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting...

Hög CVE-2018-8711

CVE-2018-8711: A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action....

Påverkade versioner: < 2.2.0

A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The vulnerability is due to the lack of args/input v...

Hög CVE-2018-8710

CVE-2018-8710: A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action...

Påverkade versioner: < 2.2.0

A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function...

Medel CVE-2015-2329

CVE-2015-2329: Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

Påverkade versioner: < 2.3.6

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

Medel CVE-2018-5316

CVE-2018-5316: The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.

Påverkade versioner: < 1.0.9

The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.

Hög CVE-2017-17058

CVE-2017-17058: The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: ...

Påverkade versioner: <= 3.2.6

The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traver...

Låg CVE-2016-10112

CVE-2016-10112: Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted ...

Påverkade versioner: <= 2.6.8

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.

Medel CVE-2015-5065

CVE-2015-5065: Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to re...

Påverkade versioner: < 1.4

Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl...

Medel CVE-2015-2069

CVE-2015-2069: Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports ...

Påverkade versioner: <= 2.2.10

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php.

Medel CVE-2014-6313

CVE-2014-6313: Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-report...

Påverkade versioner: <= 2.2.2

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin/admin.php.

Medel CVE-2014-4549

CVE-2014-4549: Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject ar...

Påverkade versioner: <= 0.1.6.6

Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MD or (2) PARe...

Så skyddar du din sajt

Sårbarheter i tillägg är den vanligaste attackytan för WordPress-sajter. Det bästa skyddet är att vara proaktiv — här är tre konkreta steg.

Håll tillägget uppdaterat

De flesta sårbarheter i WooCommerce åtgärdas snabbt av utvecklarna. Uppdatera alltid till senaste versionen.

Ta bort oanvända tillägg

Varje tillägg är en potentiell attackyta. Avinstallera det du inte aktivt använder.

Bevaka automatiskt

Med löpande övervakning upptäcker du problem innan de blir allvarliga.

Vill du slippa hålla koll själv? Med ett supportavtal från Sitesupport sköter vi uppdateringar och säkerhet åt dig.

Vanliga frågor om WooCommerce

WooCommerce har 52 kända sårbarheter, varav 14 med hög eller kritisk allvarlighetsgrad. Det betyder inte nödvändigtvis att tillägget är osäkert — de flesta sårbarheter åtgärdas i nya versioner. Det viktigaste är att alltid köra den senaste versionen.
Det enklaste sättet är att köra ett gratis test av din hemsida på sitesupport.co. Testet kontrollerar vilka tillägg du använder och vilka versioner som är installerade, och jämför det mot kända sårbarheter.
Uppdatera till den senaste versionen så snart som möjligt. Om det inte finns en uppdatering som åtgärdar problemet bör du överväga att tillfälligt inaktivera tillägget, särskilt om sårbarheten har kritisk eller hög allvarlighetsgrad.
WooCommerce har över 7 000 000 aktiva installationer på WordPress.org och ett betyg på 4.5 av 5. Populära tillägg har generellt bättre säkerhetsrutiner tack vare större community och fler ögon på koden.

Hur mår din hemsida?

Kör ett gratis test och se hur din sajt presterar inom SEO, säkerhet, prestanda och tillgänglighet — på under en minut.

Testa gratis

Inget konto krävs