WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 672 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High WPC Product Options for WooCommerce Plugin wpc-product-options Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name No login needed ≤ 4.0.5 CVE-2026-97660 Wordfence
8.6 High SaveTo Wishlist Lite Plugin saveto-wishlist-lite-for-woocommerce SQL Injection Unauthenticated SQLi via 'sort_column' and 'sort_order' Parameters No login needed < 1.1.5 Fixed in 1.1.5 CVE-2026-89236 WPScan
8.1 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter No login needed ≤ 1.2.30 CVE-2026-101923 Wordfence
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Author Name No login needed ≤ 5.122.0 CVE-2026-97663 Wordfence
7.5 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100517 Patchstack
7.6 High Gratisfaction Plugin gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce Broken Access Control ≤ 4.6.3 Fixed in 4.6.4 CVE-2026-97297 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97273 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97268 Patchstack
7.2 High Hide Shipping Method For WooCommerce Plugin hide-shipping-method-for-woocommerce PHP Object Injection ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-94390 Patchstack
8.5 High BuildKit – Product Builder for WooCommerce – Custom PC Builder Plugin woo-product-builder SQL Injection Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection ≤ 1.0.28 Fixed in 1.0.29 CVE-2026-102379 Patchstack
8.8 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint ≤ 2.0.0 CVE-2026-95687 Wordfence
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields No login needed ≤ 5.16.1 CVE-2026-92244 Wordfence
7.2 High Extra Product Options For WooCommerce | Custom Product Addons and Fields Plugin woo-extra-product-options PHP Object Injection ≤ 3.3.8 Fixed in 3.3.9 CVE-2026-102392 Patchstack
7.1 High Premmerce Permalink Manager for WooCommerce Plugin woo-permalink-manager Cross-Site Scripting No login needed ≤ 2.3.13 Fixed in 2.3.16 CVE-2026-97272 Patchstack
8.8 High Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification Plugin wc-blacklist-manager Cross-Site Request Forgery WooCommerce Anti-Fraud, Blacklist & Checkout Verification plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-96838 Patchstack
7.6 High Category Discount Woocommerce Plugin woo-product-category-discount SQL Injection ≤ 5.18 Fixed in 5.19 CVE-2026-96828 Patchstack
7.5 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 5.120.0 Fixed in 5.121.0 CVE-2026-96823 Patchstack
8.2 High MakeCommerce for WooCommerce Plugin makecommerce Broken Access Control No login needed ≤ 4.1.0 Fixed in 4.1.1 CVE-2026-96817 Patchstack
7.1 High Trusted Shops Easy Integration for WooCommerce Plugin trusted-shops-easy-integration-for-woocommerce Cross-Site Scripting No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2026-96816 Patchstack
7.1 High WooCommerce Product Table Lite Plugin wc-product-table-lite Cross-Site Scripting No login needed ≤ 5.6.7 Fixed in 5.6.9 CVE-2026-96814 Patchstack
7.1 High YITH WooCommerce Ajax Search Plugin yith-woocommerce-ajax-search Cross-Site Scripting No login needed ≤ 2.28.0 Fixed in 2.28.1 CVE-2026-96352 Patchstack
7.2 High Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer PHP Object Injection ≤ 1.5.19.1 Fixed in 1.5.19.2 CVE-2026-94677 Patchstack
7.2 High Cost of Goods for WooCommerce Plugin cost-of-goods-for-woocommerce PHP Object Injection ≤ 3.5.2 Fixed in 4.2.1 CVE-2026-93771 Patchstack
7.2 High Minimum and Maximum Quantity for WooCommerce Plugin min-and-max-quantity-for-woocommerce PHP Object Injection ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-93651 Patchstack
7.2 High Music Player for WooCommerce Plugin music-player-for-woocommerce PHP Object Injection ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-93624 Patchstack
8.8 High All in One Files Upload for WooCommerce Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG Upload No login needed 2.0.3 – < 2.0.17 Fixed in 2.0.17 CVE-2026-85573 WPScan
7.3 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed < 2.0.8 Fixed in 2.0.8 CVE-2026-93928 Patchstack
7.2 High WPC Product Bundles for WooCommerce Plugin woo-product-bundle Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter No login needed ≤ 8.6.6 CVE-2026-93836 Wordfence
8.1 High HUSKY Plugin woocommerce-products-filter Local File Inclusion Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX No login needed ≤ 1.4.4 CVE-2026-92969 Wordfence
7.5 High MgoSync Plugin megamo Information Disclosure Unauthenticated WooCommerce API Credential Disclosure No login needed 2.1.5 – < 2.1.7 Fixed in 2.1.7 CVE-2026-92404 WPScan
7.5 High Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration Path Traversal Unauthenticated Arbitrary File Read via 'folder' and 'mockups' Parameters No login needed ≤ 2.8.5 CVE-2026-14323 Wordfence
8.6 High Price Drop Alert for WooCommerce Plugin SQL Injection Unauthenticated SQL Injection via product No login needed ≤ 1.1 CVE-2026-87770 WPScan
7.6 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert SQL Injection ≤ 1.9.21 Fixed in 2.0.0 CVE-2026-66631 Patchstack
8.5 High Product Feed Manager Plugin best-woocommerce-feed SQL Injection ≤ 7.12.0 Fixed in 7.12.1 CVE-2026-66580 Patchstack
7.5 High Choose User Role at Registration for WooCommerce Plugin Privilege Escalation Unauthenticated Privilege Escalation via Registration Role Request No login needed < 1.3.3 Fixed in 1.3.3 CVE-2026-85128 WPScan
8.6 High Ni WooCommerce Sales Report Plugin ni-woocommerce-sales-report SQL Injection Unauthenticated SQLi via 'sort' Parameter No login needed < 4.2.0 Fixed in 4.2.0 CVE-2026-78472 WPScan
7.1 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint 5.0.0 – < 5.0.16 Fixed in 5.0.16 CVE-2026-74926 WPScan
7.5 High Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce Plugin wp-event-solution Privilege Escalation Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter ≤ 4.1.23 CVE-2026-75983 Wordfence
7.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Privilege Escalation Store Owner+ Privilege Escalation to Administrator 5.0.0 – < 5.0.16 Fixed in 5.0.16 CVE-2026-74925 WPScan
7.5 High Return Refund and Exchange For WooCommerce Plugin woo-refund-and-exchange-lite Broken Access Control No login needed ≤ 4.6.4 CVE-2026-81799 Patchstack
7.5 High Shirt Product Designer for WooCommerce Plugin woo-shirt-product-designer Broken Access Control No login needed 1.0.4 CVE-2026-81794 Patchstack
8.6 High Advanced Product Fields Extended for WooCommerce Plugin advanced-product-fields-for-woocommerce-extended Arbitrary File Deletion No login needed ≤ 3.1.6 Fixed in 3.1.7 CVE-2026-81789 Patchstack
7.5 High Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control No login needed ≤ 1.2.2 CVE-2026-81786 Patchstack
7.2 High Registration Form for WooCommerce Plugin registration-form-for-woocommerce Privilege Escalation Contributor+ Privilege Escalation via Unvalidated tgwcfb_id 1.1.0 – < 1.1.3 Fixed in 1.1.3 CVE-2026-81431 WPScan
7.5 High Ultimate Gift Cards for WooCommerce Plugin woo-gift-cards-lite Information Disclosure Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_details No login needed 3.0.3 – < 3.2.10 Fixed in 3.2.10 CVE-2026-19439 WPScan
7.5 High Ultimate Gift Cards For WooCommerce Plugin woo-gift-cards-lite Broken Access Control Unauthenticated Gift Card Value Inflation via Discounted Purchase No login needed < 3.2.10 Fixed in 3.2.10 CVE-2026-19436 WPScan
7.5 High Direct Download for WooCommerce Plugin direct-download-for-woocommerce Path Traversal Unauthenticated Arbitrary File Read via 'file_id' Path Segment No login needed ≤ 1.19 CVE-2026-15019 Wordfence
8.8 High YITH WooCommerce Waitlist Premium Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user ≤ 3.35.0 CVE-2026-14359 Wordfence
8.6 High ELEX WooCommerce Request a Quote Plugin elex-request-a-quote SQL Injection Unauthenticated SQLi via variation_id No login needed < 2.4.1 Fixed in 2.4.1 CVE-2026-14962 WPScan
8.1 High Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration Authentication Bypass Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint No login needed ≤ 3.9.8 CVE-2026-76009 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only