WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–50 of 245 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Payflex Payment Gateway | Cross-Site Scripting No login needed |
≤ 2.7.1 Fixed in 2.8.0 |
CVE-2026-103346 |
Patchstack | |
| 5.3 Medium | Deema Payment Gateway | Authentication Bypass Unauthenticated Payment Confirmation Forgery via Unverified Success Return No login needed |
≤ 1.1.2 |
CVE-2026-94271 |
WPScan | |
| 5.3 Medium | Deema Payment Gateway | Price Manipulation Unauthenticated Payment Bypass and Order Manipulation via Webhook No login needed |
≤ 1.1.2 |
CVE-2026-94270 |
WPScan | |
| 7.5 High | Morning for WooCommerce | Broken Access Control No login needed |
≤ 2.4.1 |
CVE-2026-39723 |
Patchstack | |
| 5.3 Medium | UPI QR Code Payment Gateway | Broken Access Control Unauthenticated Cross-Order Payment-Status Forgery No login needed |
≤ 1.4.3 |
CVE-2026-84169 |
WPScan | |
| 4.3 Medium | WP User Frontend | Broken Access Control Subscriber+ Post Creation via Subscription-Gated Form |
< 4.3.12 Fixed in 4.3.12 |
CVE-2026-79618 |
WPScan | |
| 5.3 Medium | Paytm Payment Gateway | Authentication Bypass Unauthenticated Order Status Manipulation via Payment Callback No login needed |
< 2.8.9 Fixed in 2.8.9 |
CVE-2026-81740 |
WPScan | |
| 7.2 High | Business Essentials for Contact Form 7 | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed |
≤ 1.2.1 |
CVE-2026-97661 |
Wordfence | |
| 7.5 High | Payments for Hubtel | Information Disclosure Unauthenticated Payment Gateway Credentials Disclosure via Debug Log No login needed |
< 1.0.2 Fixed in 1.0.2 |
CVE-2026-96255 |
WPScan | |
| 7.5 High | Paytm Payment Gateway | SQL Injection Unauthenticated SQLi via Payment Callback No login needed |
< 2.8.9 Fixed in 2.8.9 |
CVE-2026-81809 |
WPScan | |
| 7.5 High | Paytm Payment Gateway | Cross-Site Scripting Unauthenticated Stored XSS via Payment Callback No login needed |
< 2.8.9 Fixed in 2.8.9 |
CVE-2026-81739 |
WPScan | |
| 6.5 Medium | Conekta Payment Gateway | Broken Access Control No login needed |
≤ 6.2.4 Fixed in 6.2.5 |
CVE-2026-95527 |
Patchstack | |
| 6.5 Medium | PayPlus Payment Gateway | Broken Access Control No login needed |
≤ 8.2.5 Fixed in 8.2.6 |
CVE-2026-93620 |
Patchstack | |
| 5.3 Medium | SUMIT Payment Gateway for WooCommerce | Authentication Bypass Unauthenticated Payment Confirmation Forgery via bit IPN No login needed |
< 4.0.0 Fixed in 4.0.0 |
CVE-2026-84091 |
WPScan | |
| 4.7 Medium | Paymob for WooCommerce | Broken Access Control Contributor+ Payment Gateway Configuration Deletion and Modification via Multiple AJAX Actions |
< 4.1.14 Fixed in 4.1.14 |
CVE-2026-87981 |
WPScan | |
| 8.6 High | JetFormBuilder Stripe Gateway | SQL Injection Unauthenticated Blind SQLi via Payment Token No login needed |
< 1.1.0 Fixed in 1.1.0 |
CVE-2022-4997 |
WPScan | |
| 5.3 Medium | Payment Gateway for PayPal on WooCommerce | Price Manipulation Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion No login needed |
< 9.2.1 Fixed in 9.2.1 |
CVE-2026-92400 |
WPScan | |
| 4.9 Medium | GoPay for WooCommerce | SQL Injection Authenticated (Shop Manager+) SQL Injection via 'log_table_filter' Parameter |
≤ 1.0.36 |
CVE-2026-75959 |
Wordfence | |
| 5.3 Medium | Payment Gateway of Stripe for WooCommerce | Other Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint No login needed |
≤ 5.0.8 |
CVE-2026-9832 |
Wordfence | |
| 3.7 Low | Robokassa payment gateway for Woocommerce | Price Manipulation Unauthenticated Payment Bypass via Forged JWT Callback No login needed |
< 1.8.9 Fixed in 1.8.9 |
CVE-2026-91017 |
WPScan | |
| 4.9 Medium | Event Booking Manager for WooCommerce | Information Disclosure Contributor+ Payment Gateway Credential Disclosure |
5.3.6 – < 5.6.0 Fixed in 5.6.0 |
CVE-2026-91019 |
WPScan | |
| 10.0 Critical | CryptoPayment Gateway | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router No login needed |
1.2.1 – 1.2.2 |
CVE-2026-81648 |
WPScan | |
| 8.8 High | Gato GraphQL | Privilege Escalation |
≤ 19.2.3 Fixed in 19.2.4 |
CVE-2026-62102 |
Patchstack | |
| 5.9 Medium | WC PayPay Gateway | Price Manipulation Unauthenticated Payment Bypass via Unverified Webhook No login needed |
0.5 – 0.9.3 |
CVE-2026-82215 |
WPScan | |
| 6.5 Medium | Robokassa payment gateway for Woocommerce | Broken Access Control No login needed |
≤ 1.8.9 |
CVE-2026-78536 |
Patchstack | |
| 5.3 Medium | ePayco Payment Gateway for WooCommerce | Other Unauthenticated Payment Confirmation Bypass No login needed |
< 8.4.7 Fixed in 8.4.7 |
CVE-2026-84043 |
WPScan | |
| 5.3 Medium | WP User Frontend | Broken Access Control Unauthenticated Post Creation via Subscription-Gated Form No login needed |
< 4.3.11 Fixed in 4.3.11 |
CVE-2026-17563 |
WPScan | |
| 9.1 Critical | Total Processing Card Payments for WooCommerce | Server-Side Request Forgery Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure No login needed |
≤ 7.3 |
CVE-2026-16947 |
WPScan | |
| 7.2 High | Customer Reviews for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form No login needed |
≤ 5.106.0 |
CVE-2026-6176 |
Wordfence | |
| 9.3 Critical | Epayco | SQL Injection No login needed |
≤ 8.4.6 Fixed in 8.4.7 |
CVE-2026-78260 |
Patchstack | |
| 5.3 Medium | Conekta Payment Gateway | Broken Access Control Unauthenticated Order Payment Completion via Webhook Forgery No login needed |
< 6.2.2 Fixed in 6.2.2 |
CVE-2026-16738 |
WPScan | |
| 9.8 Critical | TabaPay Gateway | Privilege Escalation Unauthenticated Account Takeover via Payment Callback No login needed |
≤ 1.4.0 |
CVE-2026-18031 |
WPScan | |
| 6.5 Medium | Flutterwave WooCommerce | Authentication Bypass Broken Authentication No login needed |
≤ 3.3.0 |
CVE-2026-73399 |
Patchstack | |
| 6.5 Medium | Piraeus Bank WooCommerce Payment Gateway | Authentication Bypass Broken Authentication No login needed |
3.2.0 |
CVE-2026-73398 |
Patchstack | |
| 7.5 High | Duitku Payment Gateway | Information Disclosure Sensitive Data Exposure No login needed |
≤ 2.11.14 |
CVE-2026-32468 |
Patchstack | |
| 4.3 Medium | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI | Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints |
≤ 3.5.2 |
CVE-2026-13167 |
Wordfence | |
| 5.3 Medium | Revolut Gateway for WooCommerce | Broken Access Control No login needed |
< 4.22.10 Fixed in 4.22.10 |
CVE-2026-73353 |
Patchstack | |
| 7.5 High | SMEPay: UPI Gateway for WooCommerce | Price Manipulation Payment Bypass No login needed |
≤ 1.0.5 |
CVE-2026-66461 |
Patchstack | |
| 7.5 High | Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) | Broken Access Control No login needed |
≤ 1.0.7 Fixed in 1.0.8 |
CVE-2026-66431 |
Patchstack | |
| 6.5 Medium | Secure Card Gateway for ePay Paycenter (Piraeus Bank) | Broken Access Control No login needed |
≤ 1.0.32 Fixed in 1.0.33 |
CVE-2026-61978 |
Patchstack | |
| 5.3 Medium | Payment Gateway for PayPal on WooCommerce | Price Manipulation Unauthenticated Payment Bypass via PayPal Advanced Return Handler No login needed |
< 9.2.1 Fixed in 9.2.1 |
CVE-2026-16621 |
WPScan | |
| 5.5 Medium | RSS Aggregator by Feedzy | Broken Access Control Author+ Cross-User Import Job Manipulation and Post Deletion |
< 5.2.6 Fixed in 5.2.6 |
CVE-2026-18934 |
WPScan | |
| 9.1 Critical | MStore API | Price Manipulation Unauthenticated Payment Bypass via Multiple Payment Gateways No login needed |
< 4.21.0 Fixed in 4.21.0 |
CVE-2026-16038 |
WPScan | |
| 7.5 High | Payment Gateway for Redsys & WooCommerce Lite | Other Unauthenticated Payment Confirmation via Unverified Inespay Callback No login needed |
< 7.0.2 Fixed in 7.0.2 |
CVE-2026-12584 |
WPScan | |
| 6.5 Medium | WC Buckaroo BPE Gateway | Broken Access Control Subscriber+ Unauthorized Order Refund |
< 4.9.0 Fixed in 4.9.0 |
CVE-2026-13329 |
WPScan | |
| 5.3 Medium | GiveWP | Broken Access Control Unauthenticated Payment Gateway Restriction Bypass No login needed |
< 4.16.3 Fixed in 4.16.3 |
CVE-2026-14317 |
WPScan | |
| 5.3 Medium | The Events Calendar | Broken Access Control Unauthenticated Event Aggregator Import Status Manipulation No login needed |
< 6.16.5.1 Fixed in 6.16.5.1 |
CVE-2026-13390 |
WPScan | |
| 7.5 High | Clover Payment Gateway by Zaytech for WooCommerce | Price Manipulation Unauthenticated Payment Bypass via check_order No login needed |
< 1.3.6 Fixed in 1.3.6 |
CVE-2026-12493 |
WPScan | |
| 4.3 Medium | Zarinpal Gateway | Cross-Site Request Forgery No login needed |
≤ 5.1.0 Fixed in 5.1.1 |
CVE-2026-65460 |
Patchstack | |
| 7.5 High | Payment Gateway for PayPal on WooCommerce | Broken Access Control No login needed |
≤ 9.1.4 Fixed in 9.1.5 |
CVE-2026-59547 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.