WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 73 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Payflex Payment Gateway Plugin payflex-payment-gateway Cross-Site Scripting No login needed ≤ 2.7.1 Fixed in 2.8.0 CVE-2026-103346 Patchstack
7.5 High Morning for WooCommerce Plugin wc-gateway-greeninvoice Broken Access Control No login needed ≤ 2.4.1 CVE-2026-39723 Patchstack
7.2 High Business Essentials for Contact Form 7 Plugin cf7-redirect-thank-you-page Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed ≤ 1.2.1 CVE-2026-97661 Wordfence
7.5 High Payments for Hubtel Plugin payments-hubtel Information Disclosure Unauthenticated Payment Gateway Credentials Disclosure via Debug Log No login needed < 1.0.2 Fixed in 1.0.2 CVE-2026-96255 WPScan
7.5 High Paytm Payment Gateway Plugin paytm-payments SQL Injection Unauthenticated SQLi via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81809 WPScan
7.5 High Paytm Payment Gateway Plugin paytm-payments Cross-Site Scripting Unauthenticated Stored XSS via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81739 WPScan
8.6 High JetFormBuilder Stripe Gateway Plugin SQL Injection Unauthenticated Blind SQLi via Payment Token No login needed < 1.1.0 Fixed in 1.1.0 CVE-2022-4997 WPScan
8.8 High Gato GraphQL Plugin gatographql Privilege Escalation ≤ 19.2.3 Fixed in 19.2.4 CVE-2026-62102 Patchstack
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form No login needed ≤ 5.106.0 CVE-2026-6176 Wordfence
7.5 High Duitku Payment Gateway Plugin duitku-social-payment-gateway Information Disclosure Sensitive Data Exposure No login needed ≤ 2.11.14 CVE-2026-32468 Patchstack
7.5 High SMEPay: UPI Gateway for WooCommerce Plugin smepay-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 1.0.5 CVE-2026-66461 Patchstack
7.5 High Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) Plugin clink-gateway-for-woocommerce Broken Access Control No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2026-66431 Patchstack
7.5 High Payment Gateway for Redsys & WooCommerce Lite Plugin woo-redsys-gateway-light Other Unauthenticated Payment Confirmation via Unverified Inespay Callback No login needed < 7.0.2 Fixed in 7.0.2 CVE-2026-12584 WPScan
7.5 High Clover Payment Gateway by Zaytech for WooCommerce Plugin woo-clover-gateway-by-zaytech Price Manipulation Unauthenticated Payment Bypass via check_order No login needed < 1.3.6 Fixed in 1.3.6 CVE-2026-12493 WPScan
7.5 High Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Broken Access Control No login needed ≤ 9.1.4 Fixed in 9.1.5 CVE-2026-59547 Patchstack
7.2 High CorvusPay WooCommerce Payment Gateway Plugin corvuspay-woocommerce-integration Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter No login needed ≤ 2.7.4 CVE-2026-6939 Wordfence
7.2 High Custom Payment Gateways for WooCommerce Plugin custom-payment-gateways-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'alg_wc_cpg_input_fields' Parameter No login needed ≤ 2.1.0 CVE-2026-7517 Wordfence
8.8 High Frisbii Pay Plugin reepay-checkout-gateway Privilege Escalation ≤ 1.8.2 Fixed in 1.8.2.1 CVE-2026-56038 Patchstack
7.5 High CorvusPay WooCommerce Payment Gateway Plugin corvuspay-woocommerce-integration Authentication Bypass Broken Authentication No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2026-56029 Patchstack
8.1 High Gat Theme gat Local File Inclusion No login needed ≤ 1.16 CVE-2025-69145 Patchstack
7.5 High ABC Crypto Checkout Plugin payerurl-crypto-currency-payment-gateway-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-52695 Patchstack
7.5 High Conekta Payment Gateway Plugin conekta-payment-gateway Information Disclosure Sensitive Data Exposure No login needed ≤ 6.0.0 Fixed in 6.0.1 CVE-2026-49066 Patchstack
7.5 High Redsys for WooCommerce Light Plugin woo-redsys-gateway-light Broken Access Control No login needed ≤ 7.0.0 Fixed in 7.0.1 CVE-2026-40741 Patchstack
7.5 High IDPay Payment Gateway for Woocommerce Plugin woo-idpay-gateway Information Disclosure Sensitive Data Exposure No login needed ≤ 2.2.5 CVE-2026-34891 Patchstack
8.6 High Eupago Gateway For Woocommerce Plugin eupago-gateway-for-woocommerce Broken Access Control Unauthenticated Arbitrary Refund Initiation No login needed < 4.7.2 Fixed in 4.7.2 CVE-2026-7862 WPScan
8.8 High WP Mail Gateway Plugin wp-mail-gateway Broken Access Control Missing Authorization to Authenticated (Subscriber+) SMTP Configuration Modification via 'wmg_save_provider_config' AJAX Action ≤ 1.8 CVE-2026-6963 Wordfence
7.5 High Payment Gateway for Redsys & WooCommerce Lite Plugin woo-redsys-gateway-light Other Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation No login needed ≤ 7.0.0 CVE-2026-5050 Wordfence
7.5 High Accept Cryptocurrencies with Plisio Plugin plisio-payment-gateway-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 2.0.5 CVE-2026-6372 Patchstack
7.2 High RSS Aggregator Plugin wp-rss-aggregator Cross-Site Scripting Reflected Cross-Site Scripting via 'template' Parameter No login needed ≤ 5.0.10 CVE-2026-1216 Wordfence
7.7 High Zarinpal Gateway for WooCommerce Plugin zarinpal-woocommerce-payment-gateway Broken Access Control Improper Access Control to Payment Status Update No login needed ≤ 5.0.16 CVE-2026-2592 Wordfence
7.5 High BlueSnap Payment Gateway for WooCommerce Plugin bluesnap-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Manipulation No login needed ≤ 3.4.0 CVE-2026-0692 Wordfence
7.5 High Yoco Payments Plugin yoco-payment-gateway Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 3.9.0 CVE-2025-13801 Wordfence
8.2 High iPaymu Payment Gateway for WooCommerce Plugin ipaymu-for-woocommerce Price Manipulation Missing Authentication to Unauthenticated Payment Bypass and Order Information Disclosure No login needed ≤ 2.0.2 CVE-2026-0656 Wordfence
7.5 High Payment Plugins Braintree For WooCommerce Plugin woo-payment-gateway Broken Access Control Missing Authorization to Payment Token Exposure and Transaction Fraud No login needed ≤ 3.2.78 CVE-2025-12903 Wordfence
7.5 High Crypto Payment Gateway with Payeer for WooCommerce Plugin crypto-payment-gateway-with-payeer-for-woocommerce Price Manipulation Unauthenticated Payment Bypass No login needed ≤ 1.0.3 CVE-2025-11890 Wordfence
7.1 High Robokassa payment gateway for Woocommerce Plugin robokassa Cross-Site Scripting No login needed ≤ 1.8.6 CVE-2025-49958 Patchstack
7.5 High WooCommerce Payment Gateway for Saferpay Plugin woocommerce-payment-gateway-for-saferpay Path Traversal No login needed ≤ 0.4.9 CVE-2025-48317 Patchstack
7.5 High Order Tip for WooCommerce Plugin order-tip-woo Broken Access Control Unauthenticated Tip Manipulation to Negative Value Leading to Unauthorized Discounts No login needed ≤ 1.5.4 CVE-2025-6025 Wordfence
8.5 High Navigation Tree Elementor Plugin navigation-tree-elementor SQL Injection ≤ 1.0.1 CVE-2025-30562 Patchstack
7.1 High Pays – WooCommerce Payment Gateway Plugin axima-payment-gateway Cross-Site Request Forgery WooCommerce Payment Gateway plugin <= 2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.6 Fixed in 2.7 CVE-2025-47648 Patchstack
7.1 High Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.6 Fixed in 7.1.7 CVE-2025-32513 Patchstack
7.1 High WooCommerce TBC Credit Card Payment Gateway (Free) Plugin woo-tbc-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-32611 Patchstack
7.1 High Arigato Autoresponder and Newsletter Plugin bft-autoresponder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.2.4 Fixed in 2.7.2.5 CVE-2025-39594 Patchstack
7.1 High ABA PayWay Payment Gateway for WooCommerce Plugin aba-payway-woocommerce-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-32586 Patchstack
7.1 High WooCommerce – Payphone Gateway Plugin wc-payphone-gateway Cross-Site Scripting Payphone Gateway plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-32523 Patchstack
8.2 High CardGate Payments for WooCommerce Plugin cardgate SQL Injection No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-32119 Patchstack
7.1 High Pagopar – WooCommerce Gateway Plugin pagopar-woocommerce-gateway Cross-Site Request Forgery WooCommerce Gateway plugin <= 2.7.1 - CSRF to Stored XSS No login needed ≤ 2.7.1 Fixed in 2.8.0 CVE-2025-31032 Patchstack
7.1 High ChillPay WooCommerce Plugin chillpay-payment-gateway Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.3 Fixed in 2.6.0 CVE-2025-32570 Patchstack
7.1 High Pesapal Gateway for Woocommerce Plugin pesapal-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-30579 Patchstack
7.1 High Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.6 CVE-2025-26541 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only