WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1–35 of 35 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Flexible PDF Coupons Plugin flexible-coupons Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.14.11 Fixed in 1.14.12 CVE-2026-62081 Patchstack
4.9 Medium Tutor LMS Plugin tutor SQL Injection Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter ≤ 4.0.1 CVE-2026-15444 Wordfence
6.5 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Cross-Site Scripting ≤ 4.7.1.1 Fixed in 4.7.2 CVE-2026-39508 Patchstack
4.3 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Broken Access Control ≤ 4.7.1 Fixed in 4.7.1.1 CVE-2026-31919 Patchstack
4.3 Medium WP eCommerce Plugin Cross-Site Request Forgery Coupon Deletion via CSRF No login needed ≤ 3.15.1 CVE-2026-1128 WPScan
6.4 Medium myCred Plugin mycred Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupon' Shortcode ≤ 2.9.7.3 CVE-2026-0550 Wordfence
5.3 Medium Tutor LMS Plugin tutor Information Disclosure Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action No login needed ≤ 3.9.5 CVE-2026-1371 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification ≤ 3.9.3 CVE-2025-13628 Wordfence
5.4 Medium Couponer for Elementor Plugin couponer-elementor Broken Access Control ≤ 1.1.7 CVE-2025-66154 Patchstack
4.3 Medium WP Coupons and Deals Plugin wp-coupons-and-deals Broken Access Control ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-64241 Patchstack
4.3 Medium Depicter — Popup & Slider Builder Plugin depicter Broken Access Control Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Safe File Type Upload ≤ 4.0.4 CVE-2025-11373 Wordfence
4.3 Medium Smart Coupons for WooCommerce Plugin wt-smart-coupons-for-woocommerce Broken Access Control ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-64358 Patchstack
5.3 Medium Coupon Affiliates Plugin woo-coupon-usage Broken Access Control No login needed ≤ 7.2.0 Fixed in 7.2.1 CVE-2025-62884 Patchstack
4.3 Medium Coupon Affiliates Plugin woo-coupon-usage Broken Access Control ≤ 6.8.0 Fixed in 6.8.1 CVE-2025-59567 Patchstack
4.9 Medium Coupon API Plugin couponapi SQL Injection Authenticated (Administrator+) SQL Injection via 'log_duration' ≤ 6.2.12 CVE-2025-8692 Wordfence
6.5 Medium Coupon Affiliates Plugin woo-coupon-usage Broken Access Control Settings Change No login needed ≤ 6.4.0 Fixed in 6.4.2 CVE-2025-54025 Patchstack
6.5 Medium Coupon Affiliates Plugin woo-coupon-usage Cross-Site Request Forgery No login needed ≤ 6.4.0 Fixed in 6.4.1 CVE-2025-54022 Patchstack
6.5 Medium Coupons & Add to Cart by URL Links for WooCommerce Plugin url-coupons-for-woocommerce-by-algoritmika Cross-Site Scripting ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-48250 Patchstack
6.5 Medium tagDiv Opt-In Builder Plugin SQL Injection Authenticated (Subscriber+) SQL Injection via subscriptionCouponId Parameter ≤ 1.7 CVE-2025-2890 Wordfence
6.1 Medium Coupon Affiliates – Affiliate Plugin for WooCommerce Plugin woo-coupon-usage Cross-Site Scripting Affiliate Plugin for WooCommerce <= 6.3.0 - Reflected Cross-Site Scripting via 'commission_summary' Parameter No login needed ≤ 6.3.0 CVE-2025-3598 Wordfence
4.3 Medium Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets Plugin wpsyncsheets-woocommerce Broken Access Control ≤ 1.8.2 Fixed in 1.9 CVE-2025-22667 Patchstack
5.3 Medium Scratch & Win – Giveaways and Contests Plugin scratch-win-giveaways-for-website-facebook Broken Access Control Giveaways and Contests <= 2.8.0 - Missing Authorization to Unauthenticated Coupon Creation No login needed ≤ 2.8.0 CVE-2024-13316 Wordfence
6.5 Medium Flexible PDF Coupons Plugin flexible-coupons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.10.3 Fixed in 1.10.3 CVE-2025-22825 Patchstack
5.4 Medium Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups Plugin coupon-x-discount-pop-up Broken Access Control Missing Authorization ≤ 1.3.5 CVE-2024-12204 Wordfence
6.4 Medium Coupon Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.1 CVE-2024-12516 Wordfence
6.5 Medium Coupon Plugin coupon-lite Cross-Site Scripting ≤ 1.2.2 CVE-2024-56235 Patchstack
6.5 Medium Coupon Affiliates – Affiliate Plugin for WooCommerce Plugin woo-coupon-usage Arbitrary Shortcode Execution Affiliate Plugin for WooCommerce <= 5.16.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed ≤ 5.16.7.1 CVE-2024-12421 Wordfence
6.4 Medium Depicter — Popup & Slider Builder Plugin depicter Cross-Site Scripting Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.2.1- Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.2.1 CVE-2024-4633 Wordfence
5.3 Medium Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Plugin ays-popup-box Broken Access Control Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update No login needed ≤ 4.9.7 CVE-2024-10861 Wordfence
5.3 Medium WooCommerce Smart Coupons Plugin Broken Access Control Unauthenticated Coupon Creation No login needed < 4.6.5 Fixed in 4.6.5 CVE-2020-36841 Wordfence
4.7 Medium Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons Plugin woo-discount-rules Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed ≤ 2.6.5 CVE-2024-8541 Wordfence
5.9 Medium Coupon & Discount Code Reveal Button Plugin coupon-reveal-button Cross-Site Scripting ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-32722 Patchstack
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Coupon Search ≤ 5.46.0 CVE-2024-3869 Wordfence
5.3 Medium WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin myshopkit-popup-smartbar-slidein Information Disclosure WordPress WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin <= 1.0.9 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.0.9 CVE-2024-1436 Patchstack
5.3 Medium WPGraphQL WooCommerce Plugin Information Disclosure Unauthenticated Coupon Codes Disclosure No login needed < 0.12.4 Fixed in 0.12.4 CVE-2022-1563 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only