WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–26 of 26 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97273 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97268 Patchstack
7.1 High Premmerce Permalink Manager for WooCommerce Plugin woo-permalink-manager Cross-Site Scripting No login needed ≤ 2.3.13 Fixed in 2.3.16 CVE-2026-97272 Patchstack
9.3 Critical Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist SQL Injection No login needed ≤ 1.1.11 Fixed in 1.1.12 CVE-2026-54849 Patchstack
8.8 High Premmerce Dev Tools Plugin premmerce-dev-tools Broken Access Control Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via Plugin Creation ≤ 2.0 CVE-2026-6933 Wordfence
6.5 Medium Premmerce Redirect Manager Plugin premmerce-redirect-manager Broken Access Control ≤ <= 1.0.12 Fixed in 1.0.13 CVE-2026-32541 Patchstack
6.4 Medium Premmerce Plugin premmerce Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'premmerce_wizard_actions' AJAX Endpoint ≤ 1.3.20 CVE-2026-0555 Wordfence
6.1 Medium Premmerce WooCommerce Customers Manager Plugin woo-customers-manager Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.14 CVE-2025-13369 Wordfence
5.3 Medium Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Wishlist Deletion No login needed ≤ 1.1.10 CVE-2025-13440 Wordfence
4.3 Medium Premmerce Brands for WooCommerce Plugin premmerce-woocommerce-brands Broken Access Control Missing Authorization To Authenticated (Subscriber+) Brand Permalink Settings Update ≤ 1.2.13 CVE-2025-12783 Wordfence
7.1 High Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.1.10 CVE-2025-12411 Wordfence
7.5 High Premmerce Plugin premmerce Local File Inclusion No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-60241 Patchstack
7.5 High Premmerce Product Search for WooCommerce Plugin premmerce-search Local File Inclusion No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-60194 Patchstack
7.5 High Premmerce User Roles Plugin premmerce-user-roles Local File Inclusion No login needed ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-60193 Patchstack
7.5 High Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Local File Inclusion No login needed ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-60192 Patchstack
7.5 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Local File Inclusion No login needed ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-60191 Patchstack
5.9 Medium Premmerce User Roles Plugin premmerce-user-roles Cross-Site Scripting ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-64291 Patchstack
4.3 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-64290 Patchstack
5.9 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Scripting ≤ 2.2.7 CVE-2025-64289 Patchstack
4.3 Medium Premmerce Plugin premmerce Cross-Site Request Forgery No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-64288 Patchstack
5.4 Medium Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Broken Access Control ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-64285 Patchstack
4.3 Medium Premmerce Brands for WooCommerce Plugin premmerce-woocommerce-brands Cross-Site Request Forgery No login needed ≤ 1.2.13 Fixed in 1.2.14 CVE-2025-62890 Patchstack
4.3 Medium Premmerce User Roles Plugin premmerce-user-roles Broken Access Control ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-62883 Patchstack
8.1 High Premmerce User Roles Plugin premmerce-user-roles Broken Access Control ≤ 1.0.12 Fixed in 1.0.13 CVE-2023-41130 Patchstack
4.3 Medium Premmerce Product Filter for WooCommerce Plugin premmerce-woocommerce-product-filter Broken Access Control ≤ 3.7.2 Fixed in 3.7.3 CVE-2024-31359 Patchstack
8.3 High Premmerce Permalink Manager for WooCommerce Plugin woo-permalink-manager Local File Inclusion No login needed ≤ 2.3.10 Fixed in 2.3.11 CVE-2024-27971 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only