CVE-2026-32568: Remote Code Execution in WooCommerce Designer Pro
This text was generated using artificial intelligence (AI).CVE-2026-32568 describes a remote code execution vulnerability in WooCommerce Designer Pro (wc-designer-pro). Affected are versions up to and including 1.9.33. The vulnerability has a CVSS score of 9.9 rated.
The publication of CVE-2026-32568 took place on October 6, 2026. According to a Patchstack advisory, this is a subscriber remote code execution in WooCommerce Designer Pro up to and including version 1.9.33.
The documented vulnerability type is CWE-94: Code Injection. The CVSS vector indicates network access, low attack complexity, low privileges required, and no user interaction required. Confidentiality, integrity, and availability are each rated as having a high impact in the CVSS vector.
A specific cleaned version is not mentioned in the available information. Therefore, affected organizations should first focus on checking patch status and vulnerability.
Prioritization of Affected Systems
It is relevant whether WooCommerce Designer Pro is used in a publicly accessible web application and whether the version used falls within the affected version range. The vulnerability affects a WordPress plugin provided through the WordPress Plugin Repository.
Technical prioritization can focus on the following questions:
Is WooCommerce Designer Pro in use in a publicly accessible shop instance?
Is the version in use at 1.9.33 or below?
What is the patch status of the affected installation?
Which systems should be addressed first due to their accessibility and usage?
According to Patchstack, there were no indications of active exploitation at the time of publication. However, the CVSS score of 9.9 warrants a timely review of affected installations.
Measures to Address
The documented measures for CVE-2026-32568 are:
Check patch status and susceptibility for the vulnerability.
Prioritize and mitigate affected systems.
Establish continuous vulnerability and vendor risk monitoring.
For operators of online shops in Germany and Austria: If such a vulnerability is actively exploited and personal data of EU citizens is affected, there is a reporting obligation to the responsible data protection authority within 72 hours according to Art. 33 GDPR. Operators subject to the NIS-2 directive — implemented in Germany via the BSIG, in Austria via the NISG — must additionally meet increased requirements for vulnerability management. For companies in Switzerland, the revised Information Security Act (ISG) applies with a reporting obligation to the BACS.
LocateRisk: Visibility of Publicly Accessible Shop Systems
LocateRisk can make publicly accessible web applications and utilized software visible. This allows prioritization of WooCommerce installations in the external inventory for review.
The visibility of a utilized component does not necessarily indicate the specific vulnerable version. Therefore, version and susceptibility checking remains a separate step. For CVE-2026-32568, External Attack Surface Management supports the question of which publicly accessible shop systems and software components should be checked first.
Additionally, continuous Vendor Risk Management can connect security reports about software vendors with the use of components in one's own external infrastructure.
Am I affected?
This affects WooCommerce Designer Pro in the versions mentioned above. Those who want to know if WooCommerce Designer Pro is visible in their own externally accessible infrastructure can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-32568 is a critical security vulnerability in the WordPress plugin WooCommerce Designer Pro, which allows attackers with basic user rights (Subscriber level) to execute arbitrary code on the affected server (Remote Code Execution). The vulnerability is classified as Code Injection according to CWE-94 and rated with a CVSS score of 9.9.
All versions of WooCommerce Designer Pro up to and including 1.9.33 are affected. At the time of publication on October 6, 2026, no patched version was available. Operators should actively monitor the patch status from the vendor and secure or deactivate the installation until a fix is available.
First, it should be checked whether WooCommerce Designer Pro is operated in a publicly accessible instance in version 1.9.33 or below. If that is the case, the installation should be treated as a priority, access restricted, or the plugin deactivated until a patch is available. Additionally, continuous monitoring of the external attack surface inventory is recommended to systematically identify affected components.
Status: October 06, 2026. This contribution is for general informational purposes and does not constitute legal, security, or action advice in individual cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we do not guarantee the timeliness, accuracy, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-32568
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.