A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it has been fixed in 8.1.3. It does not affect WooCommerce 8.0 or earlier.
We have discovered 855,704 live websites that are affected by CVE-2025-15033.
| Product | |
| Category | Ecommerce |
| Vulnerable Domains | 855,704 live websites (66% of WooCommerce install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 91 versions ( 20% of all versions) |
| 256,162 websites | |
| 65,893 websites | |
| 47,211 websites | |
| 42,115 websites | |
| 33,217 websites | |
| 31,813 websites | |
| 26,150 websites | |
| 20,375 websites | |
| 20,253 websites | |
| 17,339 websites |
| .com | 396,147 websites |
| .co.uk | 30,058 websites |
| .nl | 29,739 websites |
| .de | 27,820 websites |
| .org | 26,760 websites |
| .it | 22,580 websites |
| .fr | 16,944 websites |
| .com.au | 16,162 websites |
| .com.br | 15,385 websites |
| .net | 15,376 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *** | ||
| **.*******.com | *** | ||
| *******.com | *,*** | ||
| ****.net | *,*** | ||
| ***********.com | *,*** | ||
| ******************.com | *,*** | ||
| *********.com | *,*** | ||
| **.*******.com | *,*** | ||
| ******.com | *,*** | ||
| ********.org | *,*** |
FAQ