← WordPress Vulnerabilities
WordPress security by component

Facebook for WooCommerce

Facebook for WooCommerce is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published May 27, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: facebook-for-woocommerce

CVE-2026-49059: Facebook for WooCommerce: An open redirect

Facebook for WooCommerce is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination. The published affected range is n/a through 3.7.0.

PublishedMay 27, 2026
Known safe version> 3.7.0
Safe version
May 27, 2026 CVE-2026-49059
Facebook for WooCommerce: An open redirect
Facebook for WooCommerce is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination. The published affected range is n/a through 3.7.0.
> 3.7.0
CVE4.7
NVDPending
Oct 29, 2025 CVE-2025-64296
Facebook for WooCommerce: A security weakness
Facebook for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Aug 30, 2019 CVE-2019-15841
Facebook For Woocommerce: Cross-site request forgery
Facebook For Woocommerce is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Aug 30, 2019 CVE-2019-15840
Facebook For Woocommerce: Cross-site request forgery
Facebook For Woocommerce is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8