VendorsBoosterbooster_for_woocommerceall versions
Vulnerabilities

Booster for WooCommerce

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2021-34646
Booster for WooCommerce <= 5.4.3 Authentication Bypass
Published 2021-08-30 · Modified
9.81 PoCEPSS 0.509
CVE-2024-13342
Booster for WooCommerce <= 7.2.4 - Unauthenticated Double Extension Arbitrary File Upload
Published 2025-08-29 · Analyzed
9.8EPSS 0.007
CVE-2024-13744
Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Arbitrary File Upload
Published 2025-04-04 · Analyzed
9.8EPSS 0.007
CVE-2024-1986
Elite Booster for WooCommerce <= 7.1.7 - Authenticated (Subscriber+) Arbitrary File Upload
Published 2024-03-07 · Modified
8.8EPSS 0.013
CVE-2023-48747
WordPress Booster for WooCommerce plugin <= 7.1.2 - Authenticated Production Creation/Modification Vulnerability
Published 2024-06-04 · Analyzed
8.8EPSS 0.004
CVE-2022-4017
Booster for WooCommerce - Multiple CSRF
Published 2023-01-23 · Modified
8.8EPSS 0.003
CVE-2022-3763
Booster for WooCommerce - Checkout Files Deletion via CSRF
Published 2022-11-21 · Modified
8.1EPSS 0.004
CVE-2024-3957
Booster for WooCommerce <= 7.1.8 - Unauthenticated Arbitrary Shortcode Execution
Published 2024-05-02 · Modified
7.3EPSS 0.009
CVE-2024-12278
Booster for WooCommerce <= 7.2.4 - Unauthenticated Stored Cross-Site Scripting
Published 2025-04-01 · Modified
7.2EPSS 0.003
CVE-2024-13708
Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Stored Cross-Site Scripting
Published 2025-04-04 · Analyzed
7.2EPSS 0.003
CVE-2024-29760
WordPress Booster for WooCommerce plugin <= 7.1.8 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-03-27 · Modified
7.1EPSS 0.004
CVE-2025-39446
WordPress Booster Plus for WooCommerce plugin <= 7.2.4 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2025-05-19 · Modified
7.1EPSS 0.002
CVE-2025-64196
WordPress Booster for WooCommerce plugin <= 7.2.5 - Cross Site Scripting (XSS) vulnerability
Published 2025-11-06 · Modified
7.1EPSS 0.002
CVE-2022-3762
Booster for WooCommerce - ShopManager+ Arbitrary File Download
Published 2022-11-21 · Modified
6.5EPSS 0.010
CVE-2023-40002
WordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data Exposure
Published 2023-11-22 · Modified
6.5EPSS 0.006
CVE-2023-48333
WordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data Exposure
Published 2023-11-30 · Modified
6.5EPSS 0.006
CVE-2023-52231
WordPress Booster Plus for WooCommerce plugin < 7.1.2 - Auth. Sensitive Data Exposure vulnerability
Published 2024-03-28 · Modified
6.5EPSS 0.005
CVE-2023-52234
WordPress Booster Elite for WooCommerce plugin < 7.1.2 - Auth. Sensitive Data Exposure vulnerability
Published 2024-03-28 · Modified
6.5EPSS 0.005
CVE-2023-51511
WordPress Booster Elite for WooCommerce plugin < 7.1.3 - Authenticated Production Creation/Modification Vulnerability
Published 2024-06-04 · Analyzed
6.5EPSS 0.004
CVE-2023-52230
WordPress Booster Plus for WooCommerce plugin < 7.1.3 - Authenticated Arbitrary WordPress Option Disclosure Vulnerability
Published 2024-06-09 · Modified
6.5EPSS 0.004
CVE-2022-4016
Booster for WooCommerce - Custom Role Creation/Deletion via CSRF
Published 2022-12-12 · Modified
6.5EPSS 0.003
CVE-2023-52232
WordPress Booster Plus for WooCommerce plugin < 7.1.2 - Authenticated Arbitrary Post/Page Deletion Vulnerability
Published 2024-06-09 · Modified
6.5EPSS 0.003
CVE-2025-64380
WordPress Booster for WooCommerce plugin <= 7.3.2 - Cross Site Scripting (XSS) vulnerability
Published 2025-11-13 · Modified
6.5EPSS 0.002
CVE-2023-4945
Booster for WooCommerce <= 7.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2023-09-14 · Modified
6.4EPSS 0.006
CVE-2023-5638
Booster for WooCommerce <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2023-10-19 · Modified
6.4EPSS 0.005
CVE-2024-1054
Booster for WooCommerce <= 7.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-02-20 · Modified
6.4EPSS 0.003
CVE-2024-1534
Booster for WooCommerce <= 7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortocde
Published 2024-03-07 · Modified
6.4EPSS 0.003
CVE-2018-20966
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
Published 2019-08-12 · Modified
6.1EPSS 0.018
CVE-2021-25001
Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in Product XML Feeds Module
Published 2022-01-03 · Modified
6.1EPSS 0.008
CVE-2021-25000
Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in General Module
Published 2022-01-03 · Modified
6.1EPSS 0.008
CVE-2021-24999
Booster for Woocommerce < 5.4.9 - Reflected Cross-Site Scripting in PDF Invoicing Module
Published 2022-01-03 · Modified
6.1EPSS 0.008
CVE-2024-9239
Booster for WooCommerce <= 7.2.3 - Reflected Cross-Site Scripting
Published 2024-11-20 · Analyzed
6.1EPSS 0.004
CVE-2022-4227
Booster for WooCommerce - Reflected Cross-Site Scripting
Published 2022-12-26 · Modified
6.1EPSS 0.004
CVE-2024-9170
Booster for WooCommerce <= 7.2.3 - Authenticated (ShopManager+) Stored Cross-Site Scripting via wcj_product_meta Shortcode
Published 2024-11-26 · Analyzed
5.5EPSS 0.004
CVE-2022-41805
WordPress Booster for WooCommerce plugin <= 5.6.6 - Cross-Site Request Forgery (CSRF) vulnerability
Published 2022-11-18 · Modified
5.4EPSS 0.002
CVE-2023-4796
Booster for WooCommerce <= 7.1.0 - Authenticated (Subscriber+) Information Disclosure via Shortcode
Published 2023-10-20 · Modified
4.3EPSS 0.007
CVE-2025-64379
WordPress Booster for WooCommerce plugin <= 7.4.0 - Broken Access Control vulnerability
Published 2025-11-13 · Modified
4.3EPSS 0.002