WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–16 of 16 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.7 Low NP Quote Request for WooCommerce Plugin woo-rfq-for-woocommerce Information Disclosure Unauthenticated Order Data Disclosure via Quote Request Page No login needed 2.0 – < 2.4.16 Fixed in 2.4.16 CVE-2026-93528 WPScan
2.7 Low Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Contributor+ Unpublished Event Disclosure via mpwem_load_event_list 5.3.6 – < 5.7.3 Fixed in 5.7.3 CVE-2026-91077 WPScan
3.7 Low Robokassa payment gateway for Woocommerce Plugin robokassa Price Manipulation Unauthenticated Payment Bypass via Forged JWT Callback No login needed < 1.8.9 Fixed in 1.8.9 CVE-2026-91017 WPScan
3.7 Low Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel No login needed 5.3.6 – < 5.3.8 Fixed in 5.3.8 CVE-2026-91008 WPScan
2.7 Low Comments Import & Export Plugin comments-import-export-woocommerce Information Disclosure Author+ Comment PII Disclosure via Export 2.1.11 – < 2.5.4 Fixed in 2.5.4 CVE-2026-87836 WPScan
2.2 Low BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Information Disclosure Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-84025 WPScan
3.7 Low Restore PayPal Standard for WooCommerce Plugin Price Manipulation Payment Bypass via PDT Underpayment No login needed ≤ 3.1.0 CVE-2026-17016 WPScan
3.7 Low DHL for WooCommerce Plugin Information Disclosure Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory No login needed < 4.0.1 Fixed in 4.0.1 CVE-2026-16993 WPScan
2.7 Low MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint < 5.0.11 Fixed in 5.0.11 CVE-2026-16746 WPScan
2.7 Low WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce plugin <= 6.7.24 - Broken Access Control ≤ 6.7.24 Fixed in 6.7.25 CVE-2025-54004 Patchstack
2.7 Low ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution Plugin shopengine Broken Access Control All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update ≤ 4.8.4 CVE-2025-11888 Wordfence
2.7 Low ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution Plugin Broken Access Control All in One WooCommerce Solution <= 4.8.3 - Insufficient Authorization to Authenticated (Editor+) Settings Update ≤ 4.8.3 CVE-2025-10173 Wordfence
2.7 Low Product Import Export for WooCommerce Plugin product-import-export-for-woo Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.5.0 CVE-2025-1911 Wordfence
2.7 Low Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.6.2 CVE-2025-1972 Wordfence
2.7 Low Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.6.0 CVE-2024-13922 Wordfence
3.5 Low WooCommerce Plugin woocommerce Content Injection ≤ 8.9.2 Fixed in 9.0.0 CVE-2024-35777 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only