WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices

WooCommerce wholesale plugin for serving wholesale & B2B customers. Adds wholesale pricing, user roles, dynamic pricing & more.

6Reported vulnerabilities
8.8Highest CVSS score
2.2.9Latest version
20,000+Active installs

What to do now

Update Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices to 2.2.7 or later. 6 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 3, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
WF-a7372314-fff1-42c4-99b6-10d7541d1a29 High 8.8 2.1.5 and earlier 2.1.5.1 October 19, 2022
CVE-2025-49924 High 7.2 0.4% 2.2.4.2 and earlier 2.2.5 July 23, 2025
CVE-2026-27541 High 7.2 0.2% 2.2.6 and earlier 2.2.7 February 20, 2026
CVE-2022-41640 Medium 6.4 0.4% 2.1.5 and earlier 2.1.5.1 November 28, 2022
CVE-2024-38745 Medium 5.3 0.5% 2.1.12 and earlier 2.2.0 July 11, 2024
CVE-2022-34344 Medium 4.3 0.5% 2.1.5 and earlier 2.1.6 February 27, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.