← WordPress Vulnerabilities
WordPress security by component

Booster for WooCommerce

Booster for WooCommerce is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 9.9.

Plugin slug: woocommerce-jetpack

CVE-2026-56027: Booster for WooCommerce: Dangerous file upload

Booster for WooCommerce is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 8.0.1.

PublishedJun 26, 2026
Known safe version8.0.2
Safe version
Jun 26, 2026 CVE-2026-56027
Booster for WooCommerce: Dangerous file upload
Booster for WooCommerce is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 8.0.1.
8.0.2
CVE9.9
NVDPending
Mar 17, 2026 CVE-2026-32586
Booster for WooCommerce: A security weakness
Booster for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Aug 29, 2025 CVE-2024-13342
Booster for WooCommerce: Dangerous file upload
Booster for WooCommerce is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.1
NVD9.8
Apr 04, 2025 CVE-2024-13708
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending
Apr 01, 2025 CVE-2024-12278
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Nov 26, 2024 CVE-2024-9170
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
Nov 20, 2024 CVE-2024-9239
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jun 04, 2024 CVE-2023-48747
Booster for WooCommerce: A security weakness
Booster for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD8.8
May 02, 2024 CVE-2024-3957
Woocommerce Jetpack: A security weakness
Woocommerce Jetpack is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD7.3
Mar 27, 2024 CVE-2024-29760
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Mar 07, 2024 CVE-2024-1986
Booster Elite for WooCommerce: Dangerous file upload
Booster Elite for WooCommerce is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.8
NVDPending
Nov 30, 2023 CVE-2023-48333
Booster for WooCommerce: A security weakness
Booster for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Nov 23, 2023 CVE-2023-40002
Woocommerce Jetpack: A security weakness
Woocommerce Jetpack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Oct 20, 2023 CVE-2023-4796
Woocommerce Jetpack: Sensitive information exposure
Woocommerce Jetpack is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3
Oct 19, 2023 CVE-2023-5638
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 14, 2023 CVE-2023-4945
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Nov 18, 2022 CVE-2022-41805
Woocommerce Jetpack: Cross-site request forgery
Woocommerce Jetpack is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Aug 12, 2019 CVE-2018-20966
Woocommerce Jetpack: Cross-site scripting
Woocommerce Jetpack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1