WooCommerce Plugin Security Threat - Small Business Computing

WooCommerce Plugin Security Threat

Written By
Tamara Scott
Tamara Scott
Jul 15, 2021
2 minute read

WooCommerce, a major ecommerce plugin built for WordPress sites by Automattic, warned users on Thursday, July 14, 2021, to update their plugins as soon as possible to guard against a critical security vulnerability.

In a statement posted to the WooCommerce blog on July 14, the company was first alerted to the vulnerability on July 13, 2021, and immediately began working on a patch. WooCommerce is still investigating whether customer information was or could be exposed due to the vulnerability, but the WooCommerce team did specify in a Tweet that exposed information “could include order, customer, and administrative information.”

See the full Tweet thread here:

In response to a critical vulnerability identified on July 13, 2021, we're working with the @WordPress Plugins Team to deploy software updates to users running #WooCommerce (versions 3.3 to 5.5) and the WooCommerce Blocks feature plugin (versions 2.5 to 5.5).

— WooCommerce (@WooCommerce) July 14, 2021

Also Read: Wix vs. WordPress: What Is The Best Website Builder in 2021?

How to update WooCommerce safely

WooCommerce support has provided instructions for updating its plugin without breaking a shop. Users should update to the highest number possible in their release branch to secure against the vulnerability:

“For example: If your store is running WooCommerce 4.8, first update to WooCommerce 4.8.1 – the highest version number in that branch – before going ahead and updating to WooCommerce 5.5.1.”

The ecommerce tool provider does recommend keeping your plugins up to date to the latest release and version to fully protect your site.

Problems for ecommerce sites

WordPress is the most widely used website builder tool that runs over 40% of the world’s websites. WooCommerce, which is built by the same company that provides WordPress, is a major ecommerce platform because of its close integration with WordPress.

Tamara Scott

Tamara Scott is Managing Editor at TechnologyAdvice and SmallBusinessComputing.com, where she guides content strategy, writes vendor and buyer content, and maintains high editorial standards among content creators across several properties.

Small Business Computing Logo

Small Business Computing addresses the technology needs of small businesses, which are defined as businesses with fewer than 500 employees and/or less than $7 million in annual sales. To address the needs of these small businesses, Small Business Computing offers detailed coverage of cost-effective technology solutions, including lists of top vendors, product comparisons, and how-to guides that offer specific tools to help solve issues.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.