{"id":24876,"date":"2021-07-20T09:31:08","date_gmt":"2021-07-20T14:31:08","guid":{"rendered":"https:\/\/www.webstix.com\/?p=24876"},"modified":"2021-07-20T09:31:08","modified_gmt":"2021-07-20T14:31:08","slug":"critical-vulnerability-detected-in-woocommerce","status":"publish","type":"post","link":"https:\/\/staging.webstix.net\/WSX\/wp\/support-blog\/critical-vulnerability-detected-in-woocommerce\/","title":{"rendered":"Critical Vulnerability Detected in WooCommerce"},"content":{"rendered":"<p>A <a href=\"https:\/\/woocommerce.com\/posts\/critical-vulnerability-detected-july-2021\/\" target=\"_blank\" rel=\"noopener\">critical vulnerability<\/a> concerning WooCommerce and the WooCommerce Blocks feature plugin was identified.<\/p>\n<h3>What actions should I take?<\/h3>\n<p>Automatic software updates are currently rolling out to all stores running impacted versions of each plugin \u2013 we still highly recommend you ensure that you\u2019re using the latest versions of WooCommerce and WooCommerce Blocks (5.5.1).<\/p>\n<p>To do this without causing issues, first update to the highest number possible in your release branch \u2013 this will ensure your website is no longer vulnerable.<\/p>\n<p><strong>For example:<\/strong> If your store is running WooCommerce 4.8, first update to WooCommerce 4.8.1 \u2013 the highest version number in that branch \u2013 before going ahead and updating to WooCommerce 5.5.1.<\/p>\n<p>It\u2019s always a good idea to keep up-to-date with the latest versions of WooCommerce.<\/p>\n<h3>Has any data been compromised?<\/h3>\n<p>Woocommerce investigation into this vulnerability and whether data has been compromised is ongoing. They will be sharing more information with site owners on how to investigate this security vulnerability on their site, which they will publish on their blog when it is ready. If a store was affected, the exposed information will be specific to what that site is storing but could include order, customer, and administrative information.<\/p>\n<h3>Is WooCommerce still safe to use?<\/h3>\n<p>Yes.<\/p>\n<p>Incidents like this are uncommon, but do unfortunately sometimes happen.<\/p>\n<p>Since learning of the vulnerability, the WooCommerce team has worked around the clock to ensure that a fix has been put in place, and users have been informed.<\/p>\n<p>Our continued investment in platform security allows them to prevent the vast majority of issues \u2013 but in the rare cases that could potentially impact stores, they strive to fix quickly, communicate proactively, and work collaboratively with the WooCommerce Community.<\/p>\n<h3>How do I know if my version is up-to-date?<\/h3>\n<p>The table below contains the full list of patched versions for both WooCommerce and WooCommerce Blocks. If you are running a version of WooCommerce or WooCommerce Blocks that is not on this list, please update immediately.<\/p>\n<table class=\"cls_woo\" style=\"border-collapse: collapse;margin:0px auto\">\n<tbody>\n<tr class=\"clsTabTitle\">\n<td style=\"width: 30%\"><b>Patched WooCommerce versions<\/b><\/td>\n<td style=\"width: 30%\"><b>Patched WooCommerce Blocks versions<\/b><\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">3.3.6<\/td>\n<td style=\"width: 30%\">2.5.16<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">3.4.8<\/td>\n<td style=\"width: 40%\">2.6.2<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">3.5.9<\/td>\n<td style=\"width: 40%\">2.7.2<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">3.6.6<\/td>\n<td style=\"width: 40%\">2.8.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">3.7.2<\/td>\n<td style=\"width: 40%\">2.9.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">3.8.2<\/td>\n<td style=\"width: 40%\">3.0.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">3.9.4<\/td>\n<td style=\"width: 40%\">3.1.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.0.2<\/td>\n<td style=\"width: 40%\">3.2.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.1.2<\/td>\n<td style=\"width: 40%\">3.3.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.2.3<\/td>\n<td style=\"width: 40%\">3.4.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.3.4<\/td>\n<td style=\"width: 40%\">3.5.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.4.2<\/td>\n<td style=\"width: 40%\">3.6.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.5.3<\/td>\n<td style=\"width: 40%\">3.7.2<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.6.3<\/td>\n<td style=\"width: 40%\">3.8.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.7.2<\/td>\n<td style=\"width: 40%\">3.9.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.8.1<\/td>\n<td style=\"width: 40%\">4.0.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">4.9.3<\/td>\n<td style=\"width: 40%\">4.1.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">5.0.1<\/td>\n<td style=\"width: 40%\">4.2.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">5.1.1<\/td>\n<td style=\"width: 40%\">4.3.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">5.2.3<\/td>\n<td style=\"width: 40%\">4.4.3<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">5.3.1<\/td>\n<td style=\"width: 40%\">4.5.3<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">5.4.2<\/td>\n<td style=\"width: 40%\">4.6.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\">5.5.1<\/td>\n<td style=\"width: 40%\">4.7.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\"><\/td>\n<td style=\"width: 40%\">4.8.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\"><\/td>\n<td style=\"width: 40%\">4.9.2<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\"><\/td>\n<td style=\"width: 40%\">5.0.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\"><\/td>\n<td style=\"width: 40%\">5.1.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\"><\/td>\n<td style=\"width: 40%\">5.2.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\"><\/td>\n<td style=\"width: 40%\">5.3.2<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\"><\/td>\n<td style=\"width: 40%\">5.4.1<\/td>\n<\/tr>\n<tr class=\"clsSiteDetails\">\n<td style=\"width: 40%\"><\/td>\n<td style=\"width: 40%\">5.5.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>If you need Woocommerce plugin upgrade done on your website, please <a href=\"https:\/\/staging.webstix.net\/WSX\/wp\/contact-us\/\">contact us<\/a>.<\/p>\n<p>Thank you,<br \/>\n-Webstix Support<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A critical vulnerability concerning WooCommerce and the WooCommerce Blocks feature plugin was identified. What actions should I take? Automatic software updates are currently rolling out to all stores running impacted versions of each plugin \u2013 we still highly recommend you ensure that you\u2019re using the latest versions of WooCommerce and WooCommerce Blocks (5.5.1). To do [&hellip;]<\/p>\n","protected":false},"author":468,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[6],"tags":[],"class_list":["post-24876","post","type-post","status-publish","format-standard","hentry","category-support-blog"],"acf":[],"_links":{"self":[{"href":"https:\/\/staging.webstix.net\/WSX\/wp\/wp-json\/wp\/v2\/posts\/24876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.webstix.net\/WSX\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging.webstix.net\/WSX\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging.webstix.net\/WSX\/wp\/wp-json\/wp\/v2\/users\/468"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.webstix.net\/WSX\/wp\/wp-json\/wp\/v2\/comments?post=24876"}],"version-history":[{"count":0,"href":"https:\/\/staging.webstix.net\/WSX\/wp\/wp-json\/wp\/v2\/posts\/24876\/revisions"}],"wp:attachment":[{"href":"https:\/\/staging.webstix.net\/WSX\/wp\/wp-json\/wp\/v2\/media?parent=24876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging.webstix.net\/WSX\/wp\/wp-json\/wp\/v2\/categories?post=24876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging.webstix.net\/WSX\/wp\/wp-json\/wp\/v2\/tags?post=24876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}