WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools

Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.

27Reported vulnerabilities
9.8Highest CVSS score
8.2.0Latest version
30,000+Active installs

What to do now

Update Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools to 8.0.2 or later. 27 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 5, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-13342 Critical 9.8 0.7% Before 7.2.5 7.2.5 August 29, 2025
CVE-2024-13744 Critical 9.8 0.7% 4.0.1 up to (but not including) 7.2.5 7.2.5 April 4, 2025
CVE-2024-1986 High 8.8 1.3% 0 to 7.1.7 (inclusive)
0 to 7.1.7 (inclusive)
7.1.8 March 7, 2024
CVE-2026-56027 High 8.8 0.3% 8.0.1 and earlier 8.0.2 June 23, 2026
WF-fa7ca972-ddb0-416b-8c5a-b4e9648ca957 High 8.8 5.6.8 and earlier 6.0.0 November 30, 2022
WF-2030698f-1180-432b-9a66-3039fdda79fd High 8.8 5.6.1 and earlier 5.6.2 July 27, 2022
CVE-2023-4796 Medium 4.3 0.6% Before 7.1.1 7.1.1 October 20, 2023
CVE-2024-13708 High 7.2 0.3% 4.0.1 up to (but not including) 7.2.5 7.2.5 April 4, 2025
WF-0903bd2b-240f-4791-bfa6-f727d193af4a High 7.2 7.0.0 to 7.0.0 (inclusive) 7.1.0 August 1, 2023
CVE-2024-3957 Medium 6.5 0.9% 7.1.8 and earlier 7.1.9 May 1, 2024
CVE-2018-20966 Medium 6.1 1.8% Before 3.8.0 3.8.0 August 12, 2019
CVE-2025-64380 Medium 6.4 0.2% 7.3.2 and earlier 7.4.0 October 18, 2025
CVE-2025-64196 Medium 6.1 0.2% 7.2.5 and earlier 7.2.6 April 22, 2025
CVE-2024-12278 Medium 6.1 0.3% Before 7.2.5 7.2.5 April 1, 2025
CVE-2024-9239 Medium 6.1 0.4% Before 7.2.4 7.2.4 November 20, 2024
CVE-2024-29760 Medium 6.1 0.4% 7.1.7 and earlier 7.1.8 March 25, 2024
WF-0fe5a834-487e-4da8-8b30-384427e26e6b Medium 6.1 5.5.9 and earlier 5.6.0 July 4, 2022
WF-985fd6a4-282a-48e9-9149-69e6ee794667 Medium 6.1 5.5.8 and earlier 5.5.9 May 31, 2022
CVE-2023-5638 Medium 5.4 0.5% 7.1.2 and earlier 7.1.3 October 19, 2023
CVE-2023-4945 Medium 5.4 0.5% 7.1.0 and earlier 7.1.1 September 14, 2023
CVE-2026-32586 Medium 5.3 0.2% Before 7.11.3 7.11.3 March 17, 2026
CVE-2024-9170 Medium 4.8 0.4% Before 7.2.4 7.2.4 November 26, 2024
CVE-2023-48333 Medium 4.3 0.6% 7.1.1 and earlier 7.1.2 November 24, 2023
CVE-2023-40002 Medium 4.3 0.6% 7.1.1 and earlier 7.1.2 October 4, 2023
CVE-2025-64379 Medium 4.3 0.2% 7.4.0 and earlier 7.5.0 October 30, 2025
CVE-2023-48747 Medium 4.3 0.4% 7.1.2 and earlier 7.1.3 November 24, 2023
CVE-2022-41805 Medium 4.3 0.2% Before 5.6.7 5.6.7 November 18, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.