WordPress security by component
Booster for WooCommerce
Plugin description
Booster for WooCommerce is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 9.9.
Plugin slug:
woocommerce-jetpackLatest vulnerability
CVE-2026-56027: Booster for WooCommerce: Dangerous file upload
Booster for WooCommerce is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 8.0.1.
| Safe version |
|
||
|---|---|---|---|
| Jun 26, 2026 |
CVE-2026-56027
Booster for WooCommerce: Dangerous file upload
Booster for WooCommerce is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 8.0.1.
|
8.0.2 |
CVE9.9
NVDPending
|
| Mar 17, 2026 |
CVE-2026-32586
Booster for WooCommerce: A security weakness
Booster for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 29, 2025 |
CVE-2024-13342
Booster for WooCommerce: Dangerous file upload
Booster for WooCommerce is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE8.1
NVD9.8
|
| Apr 04, 2025 |
CVE-2024-13708
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Apr 01, 2025 |
CVE-2024-12278
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Nov 26, 2024 |
CVE-2024-9170
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVD4.8
|
| Nov 20, 2024 |
CVE-2024-9239
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jun 04, 2024 |
CVE-2023-48747
Booster for WooCommerce: A security weakness
Booster for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD8.8
|
| May 02, 2024 |
CVE-2024-3957
Woocommerce Jetpack: A security weakness
Woocommerce Jetpack is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD7.3
|
| Mar 27, 2024 |
CVE-2024-29760
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Mar 07, 2024 |
CVE-2024-1986
Booster Elite for WooCommerce: Dangerous file upload
Booster Elite for WooCommerce is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 30, 2023 |
CVE-2023-48333
Booster for WooCommerce: A security weakness
Booster for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Nov 23, 2023 |
CVE-2023-40002
Woocommerce Jetpack: A security weakness
Woocommerce Jetpack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Oct 20, 2023 |
CVE-2023-4796
Woocommerce Jetpack: Sensitive information exposure
Woocommerce Jetpack is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Oct 19, 2023 |
CVE-2023-5638
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Sep 14, 2023 |
CVE-2023-4945
Booster for WooCommerce: Cross-site scripting
Booster for WooCommerce is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Nov 18, 2022 |
CVE-2022-41805
Woocommerce Jetpack: Cross-site request forgery
Woocommerce Jetpack is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Aug 12, 2019 |
CVE-2018-20966
Woocommerce Jetpack: Cross-site scripting
Woocommerce Jetpack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|