WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 2,114 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
– Not scored Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Unauthenticated Order Shipping Modification via IDOR < 4.8.8 Fixed in 4.8.8 CVE-2026-104118 WPScan
– Not scored CoCart Plugin cart-rest-api-for-woocommerce Authentication Bypass Administrator Account Creation via REST API Authentication Bypass 4.9.0 – < 4.9.7 Fixed in 4.9.7 CVE-2026-93549 WPScan
6.1 Medium WPC Estimated Delivery Date for WooCommerce Plugin wpc-estimated-delivery-date Cross-Site Scripting Reflected Cross-Site Scripting via 'rule_data' Parameter No login needed ≤ 4.0.1 CVE-2026-104313 Wordfence
7.2 High WPC Product Options for WooCommerce Plugin wpc-product-options Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name No login needed ≤ 4.0.5 CVE-2026-97660 Wordfence
5.3 Medium Mailchimp for WooCommerce Plugin mailchimp-for-woocommerce Broken Access Control Unauthenticated Abandoned Cart Modification and Deletion No login needed < 6.3 Fixed in 6.3 CVE-2026-92437 WPScan
8.6 High SaveTo Wishlist Lite Plugin saveto-wishlist-lite-for-woocommerce SQL Injection Unauthenticated SQLi via 'sort_column' and 'sort_order' Parameters No login needed < 1.1.5 Fixed in 1.1.5 CVE-2026-89236 WPScan
6.1 Medium WPC Smart Quick View for WooCommerce Plugin woo-smart-quick-view Cross-Site Scripting Reflected Cross-Site Scripting via 'woosq-redirect' Parameter No login needed ≤ 4.4.0 CVE-2026-103888 Wordfence
8.1 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter No login needed ≤ 1.2.30 CVE-2026-101923 Wordfence
4.3 Medium Helpdesk Support Ticket System for WooCommerce Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Ticket Response Deletion via 'id' Parameter ≤ 2.1.6 CVE-2026-11399 Wordfence
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor SQL Injection Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter ≤ 5.0.18 CVE-2026-12951 Wordfence
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Author Name No login needed ≤ 5.122.0 CVE-2026-97663 Wordfence
5.3 Medium WebToffee Gift Cards for WooCommerce Plugin wt-gift-cards-woocommerce Price Manipulation Unauthenticated Gift Card Amount Manipulation via wt_credit_amount No login needed < 1.3.1 Fixed in 1.3.1 CVE-2026-91020 WPScan
5.3 Medium Request a Quote Plugin get-a-quote-button-for-woocommerce Information Disclosure Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum No login needed ≤ 2.5.6 CVE-2026-90988 WPScan
6.8 Medium Tabs Responsive Plugin Cross-Site Scripting Shop Manager+ Stored XSS via WooCommerce Product Tab Content ≤ 2.5 CVE-2026-13718 WPScan
6.1 Medium Avada | Website Builder For WordPress & WooCommerce Theme Cross-Site Scripting Reflected Cross-Site Scripting via 'lang' Parameter No login needed ≤ 7.16.1 CVE-2026-84925 Wordfence
7.5 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100517 Patchstack
7.6 High Gratisfaction Plugin gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce Broken Access Control ≤ 4.6.3 Fixed in 4.6.4 CVE-2026-97297 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97273 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97268 Patchstack
7.2 High Hide Shipping Method For WooCommerce Plugin hide-shipping-method-for-woocommerce PHP Object Injection ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-94390 Patchstack
8.5 High BuildKit – Product Builder for WooCommerce – Custom PC Builder Plugin woo-product-builder SQL Injection Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection ≤ 1.0.28 Fixed in 1.0.29 CVE-2026-102379 Patchstack
5.3 Medium AFFI – Affiliate Marketing for WooCommerce Plugin affi-affiliate-marketing-for-woo Broken Access Control Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken Access Control No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2026-102390 Patchstack
8.8 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint ≤ 2.0.0 CVE-2026-95687 Wordfence
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields No login needed ≤ 5.16.1 CVE-2026-92244 Wordfence
5.4 Medium Advanced Woo Labels – Product Labels & Badges for WooCommerce Plugin advanced-woo-labels Cross-Site Scripting Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.51 CVE-2026-12241 Wordfence
7.2 High Extra Product Options For WooCommerce | Custom Product Addons and Fields Plugin woo-extra-product-options PHP Object Injection ≤ 3.3.8 Fixed in 3.3.9 CVE-2026-102392 Patchstack
5.3 Medium Pay with Vipps for WooCommerce Plugin woo-vipps Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.2.4 Fixed in 6.2.5 CVE-2026-97259 Patchstack
5.4 Medium Razorpay Payment Links for WooCommerce Plugin rzp-woocommerce Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.2.0 CVE-2026-97299 Patchstack
6.5 Medium YITH WooCommerce Tab Manager Plugin yith-woocommerce-tab-manager Cross-Site Scripting ≤ 2.15.0 Fixed in 2.15.1 CVE-2026-97292 Patchstack
7.1 High Premmerce Permalink Manager for WooCommerce Plugin woo-permalink-manager Cross-Site Scripting No login needed ≤ 2.3.13 Fixed in 2.3.16 CVE-2026-97272 Patchstack
8.8 High Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification Plugin wc-blacklist-manager Cross-Site Request Forgery WooCommerce Anti-Fraud, Blacklist & Checkout Verification plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-96838 Patchstack
7.6 High Category Discount Woocommerce Plugin woo-product-category-discount SQL Injection ≤ 5.18 Fixed in 5.19 CVE-2026-96828 Patchstack
7.5 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 5.120.0 Fixed in 5.121.0 CVE-2026-96823 Patchstack
8.2 High MakeCommerce for WooCommerce Plugin makecommerce Broken Access Control No login needed ≤ 4.1.0 Fixed in 4.1.1 CVE-2026-96817 Patchstack
7.1 High Trusted Shops Easy Integration for WooCommerce Plugin trusted-shops-easy-integration-for-woocommerce Cross-Site Scripting No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2026-96816 Patchstack
7.1 High WooCommerce Product Table Lite Plugin wc-product-table-lite Cross-Site Scripting No login needed ≤ 5.6.7 Fixed in 5.6.9 CVE-2026-96814 Patchstack
7.1 High YITH WooCommerce Ajax Search Plugin yith-woocommerce-ajax-search Cross-Site Scripting No login needed ≤ 2.28.0 Fixed in 2.28.1 CVE-2026-96352 Patchstack
7.2 High Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer PHP Object Injection ≤ 1.5.19.1 Fixed in 1.5.19.2 CVE-2026-94677 Patchstack
6.5 Medium Pixel Manager for WooCommerce Plugin woocommerce-google-adwords-conversion-tracking-tag Cross-Site Scripting ≤ 1.69.0 Fixed in 1.69.1 CVE-2026-94674 Patchstack
7.2 High Cost of Goods for WooCommerce Plugin cost-of-goods-for-woocommerce PHP Object Injection ≤ 3.5.2 Fixed in 4.2.1 CVE-2026-93771 Patchstack
7.2 High Minimum and Maximum Quantity for WooCommerce Plugin min-and-max-quantity-for-woocommerce PHP Object Injection ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-93651 Patchstack
7.2 High Music Player for WooCommerce Plugin music-player-for-woocommerce PHP Object Injection ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-93624 Patchstack
5.3 Medium YayReviews Plugin yay-customer-reviews-woocommerce Information Disclosure Unauthenticated Sensitive Data Disclosure via REST API No login needed 1.0.4 – < 1.4.1 Fixed in 1.4.1 CVE-2026-94274 WPScan
5.3 Medium InPost for WooCommerce Plugin Broken Access Control Unauthenticated Order Status Forgery via Shipment Webhook No login needed 1.7.5 – < 1.9.8 Fixed in 1.9.8 CVE-2026-93580 WPScan
4.3 Medium All in One Files Upload for WooCommerce Plugin Broken Access Control Subscriber+ Arbitrary Plugin Settings Update < 2.0.17 Fixed in 2.0.17 CVE-2026-85576 WPScan
8.8 High All in One Files Upload for WooCommerce Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG Upload No login needed 2.0.3 – < 2.0.17 Fixed in 2.0.17 CVE-2026-85573 WPScan
5.4 Medium Blacklist Manager for WooCommerce Plugin Authentication Bypass Blocked User Restriction Bypass via XML-RPC and Application Passwords 1.3.0 – < 2.3.2 Fixed in 2.3.2 CVE-2026-88828 WPScan
5.3 Medium Mailchimp for WooCommerce Plugin mailchimp-for-woocommerce Information Disclosure Unauthenticated Customer Email and Cart Disclosure via IDOR No login needed < 6.3 Fixed in 6.3 CVE-2026-92436 WPScan
9.8 Critical Request a Quote for WooCommerce Plugin get-a-quote-button-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload via AJAX Popup Handler No login needed ≤ 2.9.2 CVE-2026-18143 Wordfence
9.1 Critical Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter No login needed ≤ 5.120.0 CVE-2026-89055 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only