Known vulnerabilities in Product Configurator for WooCommerce
Allow your customers to create configurable products with a live preview of the result. Works using a layer-based system.
3Reported vulnerabilities
9.1Highest CVSS score
1.7.5Latest version
3,000+Active installs
What to do now
Update Product Configurator for WooCommerce to 1.7.3 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2022-1953 | Critical | 1.7% | Before 1.2.32 | 1.2.32 |
June 27, 2022 |
| CVE-2026-11568 | Medium | 0.5% | 1.7.2 and earlier | 1.7.3 |
June 10, 2026 |
| CVE-2025-54674 | Medium | 0.1% | 1.4.4 and earlier | 1.5.0 |
July 30, 2025 |