📦 Booster For Woocommerce

by Booster

🔍 What is Booster For Woocommerce?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-34646

CRITICAL CVSS 9.8 Aug 30, 2021

This vulnerability allows attackers to bypass authentication in the Booster for WooCommerce WordPress plugin by exploiting weak token generation in the email verification process. Attackers can impers...

CVE-2025-64196

HIGH CVSS 7.1 Nov 6, 2025

This reflected cross-site scripting (XSS) vulnerability in the Booster for WooCommerce plugin allows attackers to inject malicious scripts into web pages viewed by other users. Attackers can steal ses...

CVE-2024-13342

HIGH CVSS 8.1 Aug 29, 2025

The Booster for WooCommerce WordPress plugin allows unauthenticated attackers to upload arbitrary files with double extensions due to missing file type validation. This vulnerability affects all versi...

CVE-2024-13744

HIGH CVSS 8.1 Apr 4, 2025

The Booster for WooCommerce WordPress plugin versions 4.0.1 through 7.2.4 contain an arbitrary file upload vulnerability due to missing file type validation. Unauthenticated attackers can upload malic...

CVE-2024-12278

HIGH CVSS 7.2 Apr 1, 2025

The Booster for WooCommerce WordPress plugin has a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious scripts into website pages. These scripts e...

CVE-2024-29760

HIGH CVSS 7.1 Mar 27, 2024

This reflected cross-site scripting (XSS) vulnerability in Booster for WooCommerce allows attackers to inject malicious scripts into web pages viewed by other users. It affects WordPress sites using t...

CVE-2024-1986

HIGH CVSS 8.8 Mar 7, 2024

The Booster Elite for WooCommerce WordPress plugin allows arbitrary file uploads due to missing file type validation in the wc_add_new_product() function. This enables customer-level attackers to uplo...

CVE-2025-64380

MEDIUM CVSS 6.5 Nov 13, 2025

This stored cross-site scripting (XSS) vulnerability in the Booster for WooCommerce plugin allows attackers to inject malicious scripts into web pages that are then executed when other users view thos...

CVE-2025-64379

MEDIUM CVSS 4.3 Nov 13, 2025

This CVE describes a missing authorization vulnerability in the Pluggabl Booster for WooCommerce plugin that allows attackers to exploit incorrectly configured access control security levels. The vuln...

CVE-2023-52232

MEDIUM CVSS 6.5 Jun 9, 2024

This CVE describes a Missing Authorization vulnerability in the Booster Plus for WooCommerce WordPress plugin. Authenticated users can delete arbitrary posts and pages without proper authorization che...

CVE-2024-3957

MEDIUM CVSS 6.5 May 2, 2024

The Booster for WooCommerce plugin (also known as WooCommerce Jetpack) contains a vulnerability that allows unauthenticated attackers to execute arbitrary WordPress shortcodes. This affects all WordPr...