Known vulnerabilities in WooCommerce Square
Securely accept payments, synchronize sales, and seamlessly manage inventory and product data between WooCommerce and Square POS.
2Reported vulnerabilities
7.5Highest CVSS score
5.4.3Latest version
80,000+Active installs
What to do now
Update WooCommerce Square to 4.2.3 or later.
2 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-13457 | High | 0.3% | 4.2.0 up to (but not including) 4.2.3 4.3.0 up to (but not including) 4.3.2 4.4.0 up to (but not including) 4.4.2 4.5.0 up to (but not including) 4.5.2 4.6.0 up to (but not including) 4.6.4 4.7.0 up to (but not including) 4.7.4 4.8.0 up to (but not including) 4.8.8 4.9.0 up to (but not including) 4.9.9 5.0.0 up to (but not including) 5.0.1 5.1.0 up to (but not including) 5.1.2 |
4.2.3 |
January 10, 2026 |
| CVE-2023-35876 | Medium | 0.7% | 3.8.1 and earlier | 3.8.2 |
June 19, 2023 |