Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Booster for WooCommerce — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Booster for WooCommerce, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation report for the WordPress plugin Booster for WooCommerce, focusing on security weaknesses within this specific vendor's product line. It collects data regarding publicly disclosed security flaws, ranging from critical remote code execution risks to lower-severity information disclosure and cross-site scripting issues. The coverage spans from the plugin's initial release up to the most recent security advisory published by the vendor or tracked by third-party security databases. Visitors can use this resource to track the vendor’s history of security advisories, providing context for how quickly issues are patched and communicated to users. Additionally, one can understand broader weakness classes by seeing how common vulnerability patterns manifest in this specific ecosystem, such as improper access controls or input validation failures. The page also allows users to look up the product's complete vulnerability history, offering a chronological view of security incidents and the corresponding remediation efforts. This consolidated view helps developers and site administrators assess the overall security posture of the plugin over time, identify potential patterns in how bugs are introduced or fixed, and make informed decisions regarding plugin maintenance and update strategies. By centralizing these details, the page serves as a practical reference for auditing the plugin’s security track record without requiring searches across multiple fragmented sources.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-56027 WordPress Booster for WooCommerce plugin <= 8.0.1 - Arbitrary File Upload vulnerability CWE-434 9.9 Critical2026-06-26
CVE-2026-32586 WordPress Booster for WooCommerce plugin < 7.11.3 - Broken Access Control vulnerability CWE-862 5.3 Medium2026-03-17
CVE-2025-64380 WordPress Booster for WooCommerce plugin <= 7.3.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-11-13
CVE-2025-64379 WordPress Booster for WooCommerce plugin <= 7.4.0 - Broken Access Control vulnerability CWE-862 4.3 Medium2025-11-13
CVE-2025-64196 WordPress Booster for WooCommerce plugin <= 7.2.5 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2025-11-06
CVE-2024-13708 Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Stored Cross-Site Scripting CWE-434 7.2 High2025-04-04
CVE-2024-13744 Booster for WooCommerce 4.0.1 - 7.2.4 - Unauthenticated Arbitrary File Upload CWE-434 8.1 High2025-04-04
CVE-2023-48747 WordPress Booster for WooCommerce plugin <= 7.1.2 - Authenticated Production Creation/Modification Vulnerability CWE-287 6.5 Medium2024-06-04
CVE-2024-29760 WordPress Booster for WooCommerce plugin <= 7.1.8 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-03-27
CVE-2023-48333 WordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data Exposure CWE-200 6.5 Medium2023-11-30
CVE-2023-40002 WordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data Exposure CWE-200 6.5 Medium2023-11-22
CVE-2022-4017 Booster for WooCommerce - Multiple CSRF 8.8 -2023-01-23
CVE-2022-4227 Booster for WooCommerce - Reflected Cross-Site Scripting 6.1 -2022-12-26
CVE-2022-4016 Booster for WooCommerce - Custom Role Creation/Deletion via CSRF 6.5 -2022-12-12
CVE-2022-3763 Booster for WooCommerce - Checkout Files Deletion via CSRF 6.5 -2022-11-21
CVE-2022-3762 Booster for WooCommerce - ShopManager+ Arbitrary File Download 7.5 -2022-11-21
CVE-2021-25001 Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in Product XML Feeds Module CWE-79 6.1 -2022-01-03
CVE-2021-25000 Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in General Module CWE-79 6.1 -2022-01-03
CVE-2021-24999 Booster for Woocommerce < 5.4.9 - Reflected Cross-Site Scripting in PDF Invoicing Module CWE-79 6.1 -2022-01-03

All 19 known CVE vulnerabilities affecting Booster for WooCommerce with full Chinese analysis, references, and POCs where available.