18 Critical WooCommerce Vulnerabilities in July 2026: The Complete List of CVEs to Patch
In early July 2026, threat intelligence across the WooCommerce and WordPress ecosystems identified 18 distinct vulnerabilities (CVSS ≥ 5.0) in widely deployed extensions — including 3 critical flaws rated between 9.3 and 10.0 out of 10. Among them is a devastating supply-chain attack: a plugin compromised directly through its vendor's official update pipeline, deploying an invisible backdoor across thousands of live stores.
If you use any of the plugins below, immediate action is mandatory. Once a CVE is publicly indexed, threat actors weaponize automated exploit scripts within hours to scan and breach vulnerable storefronts.
The 3 Critical Flaws (CVSS 9.3 to 10.0)
CVE-2026-49777 — Supply-Chain Backdoor in Product Slider Pro (ShapedPlugin)
CVSS 10.0 — maximum possible severity score. Disclosed on June 3, 2026, this attack bypassed conventional application firewalls because the vendor's official release server itself was infiltrated. The malicious payload executes inside the WordPress admin dashboard, establishes a hidden fake plugin, steals administrator credentials and active 2FA sessions in plain text, and scrubs forensic traces. The campaign also infected Real Testimonials Pro and Smart Post Show Pro from the same publisher. While patched in version 3.5.4, updating alone is insufficient if your site was compromised prior to patching: all credentials and 2FA secrets must be revoked immediately.
CVE-2026-54825 & CVE-2026-49080 — Unauthenticated SQL Injections in wpDataTables
CVSS 9.3 each. wpDataTables powers interactive tables on more than 70,000 active websites — frequently rendering catalog data or order histories on WooCommerce stores. Both vulnerabilities allow remote attackers to execute arbitrary SQL commands without authentication, exposing the entire database to exfiltration. Fixed in version 7.4.1.
CVE-2026-11387 & CVE-2026-27542 — Account Takeover & Privilege Escalation (CVSS 9.8)
In SMS Alert – SMS & OTP for WooCommerce, a race condition during OTP password resets allows unauthorized privilege escalation (resolved in 3.9.6). In WooCommerce Wholesale Lead Capture, an unauthenticated privilege escalation flaw grants complete administrative account takeover (fixed in 1.17.9).
The 18 CVEs Tracked in July 2026
| Plugin | CVSS | Vulnerability Type | Fixed Version |
|---|---|---|---|
| Product Slider Pro (ShapedPlugin) | 10.0 | Supply-chain backdoor | 3.5.4 |
| SMS Alert – SMS & OTP for WooCommerce | 9.8 | Account takeover | 3.9.6 |
| WooCommerce Wholesale Lead Capture | 9.8 | Privilege escalation | 1.17.9 |
| wpDataTables (Flaw 1) | 9.3 | Unauthenticated SQL injection | 7.4.1 |
| wpDataTables (Flaw 2) | 9.3 | Unauthenticated SQL injection | 7.4.1 |
| APIExperts Square for WooCommerce | 8.5 | Blind SQL injection | 4.7.2 |
| WooCommerce PayPal Payments | 8.2 | Order manipulation | 4.0.2 |
| MainWP Child | 7.5 | Broken access control | 6.1.2 |
| WooCommerce (Core) | 7.5 | CSRF admin user creation | 10.5.3 |
| Advanced Order Export For WooCommerce | 7.1 | Stored XSS | 4.0.10 |
| Registration Form for WooCommerce | Critical* | Privilege escalation | 1.1.0 |
| WooCommerce Stripe Payment Gateway | 6.5 | Order status tampering | 10.8.0 |
| WooPayments | 6.5 | Settings tampering | 10.6.0 |
| YITH WooCommerce Wishlist | 6.5 | Unauthenticated renaming | 4.13.0 |
| GetGenie | 6.5 | Sensitive data exposure | 4.4.2 |
| Photo Gallery by FooGallery | 6.4 | Stored XSS | 3.1.32 |
| Subscriptions for WooCommerce | 5.3 | Unauthorized cancellation | 1.9.3 |
| Permalink Manager Lite | ~5-6* | Stored XSS | 2.5.3.4 |
* Qualitative score from vulnerability advisory; precise CVSS vector pending formal NVD review.
Why smaller stores are equally in the crosshairs
The belief that "hackers don't care about my small shop" is fundamentally flawed. Modern cyberattacks are completely automated: botnets continuously crawl IP ranges and search engines matching signatures of known vulnerable plugins. A store processing five orders a week is probed with the exact same exploit payloads as an enterprise portal.
Immediate Action Checklist
- Audit active plugins against the table above.
- Update immediately any matching plugin to its patched version.
- If using ShapedPlugin products: rotate all administrator credentials, database passwords, and 2FA secrets without delay.
- Inspect administrator accounts — verify that no unauthorized user roles or rogue admin accounts have been provisioned.
- Enable automatic background security updates for critical extensions.
- Review your web server and WooCommerce access logs for the past 30 days for anomalous POST requests.
🔍 Is your site running any of these vulnerable plugins?
Our automated audit detects exposed plugin versions, missing security response headers, and compromise indicators — delivering a detailed PDF report and prioritized action plan directly by email.
🔍 Audit my site now