CVE-2023-52222

WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.


We have discovered 296,051 live websites that are affected by CVE-2023-52222.

Run a Free Instant Scan




Affected Software

Product  WooCommerce
Category Ecommerce
Vulnerable Domains296,051 live websites (23% of WooCommerce install base)
Vulnerable Versions
  • from 0 through 8.2.2
Vulnerable Versions Count330 versions ( 73% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jan 8, 2024
  • Updated - Jun 17, 2025

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2023-52222
United States64,965 websites



Germany23,021 websites
France16,952 websites
Italy16,734 websites
Russia15,737 websites
GB13,307 websites
Vietnam9,989 websites
Spain9,700 websites
Netherlands8,251 websites
Poland7,563 websites

Website Distribution by TLD

Number of websites using CVE-2023-52222
.com125,852 websites
.ru12,322 websites
.it11,304 websites
.de9,010 websites
.co.uk8,206 websites
.org7,019 websites
.nl6,815 websites
.fr6,185 websites
.pl5,603 websites
.net5,590 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-52222

Top websites that are affected by CVE-2023-52222. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.com United States*,***
***********.com United States*,***
*****************.com United States*,***
*************.com United States*,***
**********.com Czech Republic*,***
*********.com United States*,***
**********.com United States*,***
*********.com Netherlands**,***
***********.net United States**,***
********.gr Greece**,***
See full domain list

FAQ

CVE-2023-52222 is Cross-Site Request Forgery (CSRF) in WooCommerce
A total of 296,051 websites have been identified as vulnerable to CVE-2023-52222, based on global website indexing conducted by WebTechSurvey.
The WooCommerce is affected by the CVE-2023-52222 vulnerability.
WooCommerce versions up to and including 8.2.2 are vulnerable to CVE-2023-52222.