Title: Immediate Patch Required
Last modified: May 5, 2025

---

# Immediate Patch Required

 *  Resolved [idayras](https://wordpress.org/support/users/idayras/)
 * (@idayras)
 * [1 year ago](https://wordpress.org/support/topic/immediate-patch-required/)
 * Hello everyone! I have received an email from [no-reply@woocommerce-secure.com](https://wordpress.org/support/topic/immediate-patch-required/no-reply@woocommerce-secure.com?output_format=md)
   saying that “We are contacting you about a critical security vulnerability detected
   in the WooCommerce platform on April 28, 2025.
   Warning: Our recent security scan,
   carried out on May 5, 2025, has validated that this critical vulnerability directly
   impacts your website: my site”
 * Recommends that I download a patch to install on my website.
 * Is this email secure?

Viewing 4 replies - 1 through 4 (of 4 total)

 *  Moderator [Support Moderator](https://wordpress.org/support/users/moderator/)
 * (@moderator)
 * [1 year ago](https://wordpress.org/support/topic/immediate-patch-required/#post-18451443)
 * Sounds fishy to me. If there is an update for Woo, it will be *here* and not 
   on some other site.
 *  [Jonayed (woo-hc)](https://wordpress.org/support/users/jonayedhosen/)
 * (@jonayedhosen)
 * [1 year ago](https://wordpress.org/support/topic/immediate-patch-required/#post-18451625)
 * Hi [@idayras](https://wordpress.org/support/users/idayras/) ,
 * Thanks for reaching out.
 * It looks like that email might be part of a phishing scam. WooCommerce hasn’t
   sent any official statement like the one you mentioned, and we’ve recently identified
   a phishing campaign targeting store owners with fake warnings about security 
   vulnerabilities.
 * These emails are designed to look legitimate but contain false information — 
   there’s no real vulnerability as claimed. You can find more details and safety
   tips in our advisory here: [https://developer.woocommerce.com/2025/04/22/dev-advisory-phishing-campaign-targeting-woocommerce-stores/](https://developer.woocommerce.com/2025/04/22/dev-advisory-phishing-campaign-targeting-woocommerce-stores/)
 * I hope this clears things up!
 *  Thread Starter [idayras](https://wordpress.org/support/users/idayras/)
 * (@idayras)
 * [1 year ago](https://wordpress.org/support/topic/immediate-patch-required/#post-18452043)
 * ok, thank you!
 *  [Jonayed (woo-hc)](https://wordpress.org/support/users/jonayedhosen/)
 * (@jonayedhosen)
 * [1 year ago](https://wordpress.org/support/topic/immediate-patch-required/#post-18452131)
 * Hi [@idayras](https://wordpress.org/support/users/idayras/) ,
 * I’m really glad we were able to point you in the right direction!
 * If you have a moment, we’d really appreciate it if you could share your experience
   by leaving us a review: [https://wordpress.org/support/plugin/woocommerce/reviews](https://wordpress.org/support/plugin/woocommerce/reviews).
   Your feedback helps us keep improving!
 * Please don’t hesitate to [create a new topic](https://wordpress.org/support/plugin/woocommerce/?view=all#new-topic-0)
   if you need further assistance.
 * Cheers!

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Immediate Patch Required’ is closed to new replies.

 * ![](https://ps.w.org/woocommerce/assets/icon.svg?rev=3234504)
 * [WooCommerce](https://wordpress.org/plugins/woocommerce/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/woocommerce/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/woocommerce/)
 * [Active Topics](https://wordpress.org/support/plugin/woocommerce/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/woocommerce/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/woocommerce/reviews/)

 * 5 replies
 * 3 participants
 * Last reply from: [Jonayed (woo-hc)](https://wordpress.org/support/users/jonayedhosen/)
 * Last activity: [1 year ago](https://wordpress.org/support/topic/immediate-patch-required/#post-18452131)
 * Status: resolved