WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce

WooCommerce features for CZ/SK e-shops: withdrawal & claim, Heureka, CRN/VAT, QR payments, delivery dates, async emails and more.

4Reported vulnerabilities
8.8Highest CVSS score
5.4.20Latest version
5,000+Active installs

What to do now

Update WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce to 5.4.17 or later. 4 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-42748 High 8.8 0.3% 5.4.1 and earlier 5.4.2 May 29, 2026
CVE-2026-12736 High 8 0.3% 0 to 5.4.16 (inclusive) 5.4.17 July 24, 2026
CVE-2024-33946 Medium 6.1 0.3% 4.0.10 and earlier 4.0.11 April 30, 2024
WF-a10da173-9b88-4599-928d-71fc42b35c50 Medium 6.1 3.5.6 and earlier 3.5.7 May 16, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.