Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Booster for WooCommerce
Pluggabl
Developer
7.6.0
Latest version
40,000
Installations
1 day ago
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Vulnerability history
0 present
31 fixed
13 Mitigation rules
Broken Access Control vulnerability
<= 7.4.0
Oct 30, 2025
Cross Site Scripting (XSS) vulnerability
<= 7.3.2
Oct 18, 2025
Unauthenticated Double Extension Arbitrary File Upload vulnerability
<= 7.2.4
Aug 29, 2025
Cross Site Scripting (XSS) vulnerability
<= 7.2.5
Apr 22, 2025
Unauthenticated Stored Cross-Site Scripting vulnerability
4.0.1-7.2.4
Apr 3, 2025
Unauthenticated Arbitrary File Upload vulnerability
4.0.1-7.2.4
Apr 3, 2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 7.2.4
Mar 31, 2025
Authenticated (ShopManager+) Stored Cross-Site Scripting via wcj_product_meta Shortcode vulnerability
<= 7.2.3
Nov 25, 2024
Reflected Cross-Site Scripting vulnerability
<= 7.2.3
Nov 19, 2024
Unauthenticated Arbitrary Shortcode Execution vulnerability
<= 7.1.8
May 1, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 7.1.7
Mar 25, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortocde vulnerability
<= 7.1.7
Mar 7, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 7.1.6
Feb 13, 2024
Authenticated Production Creation/Modification Vulnerability
<= 7.1.2
Nov 24, 2023
Auth. Arbitrary Order Information Disclosure Vulnerability
<= 7.1.1
Nov 24, 2023
Auth. Stored Cross-Site Scripting (XSS) vulnerability
<= 7.1.2
Oct 19, 2023
Authenticated Arbitrary WordPress Option Disclosure Vulnerability
<= 7.1.1
Oct 4, 2023
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 7.1.0
Sep 14, 2023
Authenticated (Subscriber+) Information Disclosure via Shortcode vulnerability
<= 7.1.0
Sep 14, 2023
Shop Manager+ Arbitrary Option Update vulnerability
<= 7.0.0
Aug 1, 2023
Multiple CSRF vulnerability
< 6.0.1
Jan 3, 2023
Cross-Site Request Forgery (CSRF) vulnerability
<= 5.6.6
Nov 21, 2022
Auth. Arbitrary File Download vulnerability
<= 5.6.6
Oct 31, 2022
Cross-Site Request Forgery (CSRF) vulnerability
<= 5.6.6
Oct 31, 2022
Cross-Site Request Forgery (CSRF) vulnerability
<= 5.6.6
Oct 28, 2022
Authenticated Order Status Update vulnerability
<= 5.6.2
Sep 19, 2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 5.5.9
Jul 4, 2022
Reflected Cross-Site Scripting (XSS) vulnerability in Product XML Feeds Module
<= 5.4.8
Dec 1, 2021
Reflected Cross-Site Scripting (XSS) vulnerability in General Module
<= 5.4.8
Dec 1, 2021
Reflected Cross-Site Scripting (XSS) vulnerability in PDF Invoicing Module
<= 5.4.8
Dec 1, 2021
Authentication Bypass vulnerability
<= 5.4.3
Aug 24, 2021