CVE-2026-49059: Facebook For Woocommerce

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.

Affected products

  • Facebook Facebook For Woocommerce: up to and including 3.7.0

Published 2026-05-27. Last modified 2026-06-17.