WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 451–500 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High WooCommerce PDF Invoices & Packing Slips Plugin woocommerce-pdf-invoices-packing-slips PHP Object Injection < 5.9.0 Fixed in 5.9.0 CVE-2026-39472 Patchstack
7.2 High WooCommerce Cart Abandonment Recovery Plugin woo-cart-abandonment-recovery Privilege Escalation < 2.1.0 Fixed in 2.1.0 CVE-2026-39470 Patchstack
9.3 Critical Feed KuantoKusta for WooCommerce – Free Plugin feed-kuantokusta-for-woocommerce SQL Injection Free plugin <= 5.3 - SQL Injection No login needed ≤ 5.3 Fixed in 5.3.1 CVE-2026-39441 Patchstack
7.2 High CTX Feed Plugin webappick-product-feed-for-woocommerce PHP Object Injection ≤ 6.6.26 Fixed in 6.6.27 CVE-2026-39434 Patchstack
7.1 High WooCommerce Product Table Lite Plugin wc-product-table-lite Cross-Site Scripting No login needed ≤ 4.6.3 Fixed in 4.6.4 CVE-2026-34902 Patchstack
7.5 High Event Tickets Manager for WooCommerce Plugin event-tickets-manager-for-woocommerce Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2026-34898 Patchstack
7.5 High IDPay Payment Gateway for Woocommerce Plugin woo-idpay-gateway Information Disclosure Sensitive Data Exposure No login needed ≤ 2.2.5 CVE-2026-34891 Patchstack
10.0 Critical WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Remote Code Execution No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-52704 Patchstack
9.8 Critical Hippoo Mobile App for WooCommerce Plugin hippoo Privilege Escalation No login needed ≤ 1.9.4 Fixed in 1.9.5 CVE-2026-49060 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Cross-Site Request Forgery No login needed ≤ 2.0.10 Fixed in 2.0.11 CVE-2022-47150 Patchstack
5.4 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Broken Access Control Broken Access Control + CSRF ≤ 1.6.3.3 Fixed in 1.6.3.4 CVE-2022-45813 Patchstack
4.6 Medium YITH WooCommerce Product Slider Carousel Plugin yith-woocommerce-product-slider-carousel Cross-Site Request Forgery ≤ 1.16.0 Fixed in 1.16.1 CVE-2022-44630 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-32110 Patchstack
4.3 Medium FastPicker, an order picker and order management system (oms) for WooCommerce on steroids Plugin fastpicker Cross-Site Request Forgery Cross-Site Request Forgery via Settings Save No login needed ≤ 1.0.2 CVE-2026-8904 Wordfence
8.1 High Recover Exit For WooCommerce Plugin recoverexit-for-woocommerce Local File Inclusion Unauthenticated Local File Inclusion via 'tpf' Parameter No login needed ≤ 1.0.3 CVE-2026-9662 Wordfence
9.8 Critical Hippoo Mobile App for WooCommerce Plugin hippoo Authentication Bypass Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API No login needed ≤ 1.9.4 CVE-2026-10580 Wordfence
10.0 Critical Product Slider Pro for WooCommerce Plugin woo-product-slider-pro Other Backdoor No login needed < 3.5.4 Fixed in 3.5.4 CVE-2026-49777 Patchstack
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Authentication Bypass Broken Authentication ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-42654 Patchstack
4.3 Medium JTL-Connector for WooCommerce Plugin woo-jtl-connector Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Modification via Multiple Functions ≤ 2.4.1 CVE-2026-9234 Wordfence
8.8 High WooCommerce Infinite Scroll and Ajax Pagination Plugin PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 1.8 CVE-2025-11993 Wordfence
4.3 Medium PeachPay Plugin peachpay-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Stripe Unlink No login needed ≤ 1.120.46 CVE-2026-9618 Wordfence
8.6 High Eupago Gateway For Woocommerce Plugin eupago-gateway-for-woocommerce Broken Access Control Unauthenticated Arbitrary Refund Initiation No login needed < 4.7.2 Fixed in 4.7.2 CVE-2026-7862 WPScan
4.3 Medium FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Broken Access Control Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated (Subscriber+) Authorization Bypass via User-Controlled Key to 'wooc_order_user_roles' Parameter ≤ 1.4.6 CVE-2026-9241 Wordfence
4.3 Medium Account Manager for WooCommerce Plugin account-manager-woocommerce Broken Access Control ≤ 2.1.2 CVE-2022-41656 Patchstack
4.7 Medium Facebook for WooCommerce Plugin facebook-for-woocommerce Open Redirect No login needed ≤ 3.7.0 CVE-2026-49059 Patchstack
4.3 Medium Product Import Export for WooCommerce Plugin product-import-export-for-woo Broken Access Control ≤ 2.5.6 Fixed in 2.5.7 CVE-2026-48971 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2026-42761 Patchstack
6.5 Medium Checkout Files Upload for WooCommerce Plugin checkout-files-upload-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.5 Fixed in 2.2.6 CVE-2026-42725 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.0.8 Fixed in 1.0.9 CVE-2026-42727 Patchstack
5.4 Medium ShopLentor - WooCommerce Builder for Elementor & Gutenberg Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute ≤ 3.3.8 CVE-2026-6287 Wordfence
7.1 High Woocommerce Envato Affiliates Plugin wooenvato Broken Access Control Settings Change ≤ 1.2.1 CVE-2025-14361 Patchstack
5.3 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-25426 Patchstack
6.5 Medium Stripe Payment Gateway for WooCommerce Plugin payment-gateway-stripe-and-woocommerce-integration Authentication Bypass Broken Authentication No login needed ≤ 5.0.7 Fixed in 5.0.8 CVE-2026-45217 Patchstack
7.5 High Smart Coupons for WooCommerce Plugin wt-smart-coupons-for-woocommerce Broken Access Control No login needed < 2.3.0 Fixed in 2.3.0 CVE-2026-45438 Patchstack
4.9 Medium B2BKing Plugin b2bking-wholesale-for-woocommerce Broken Access Control < 5.2.10 Fixed in 5.2.10 CVE-2026-27346 Patchstack
4.3 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Broken Access Control ≤ 2.14.0 CVE-2026-24527 Patchstack
8.2 High WooCommerce PayPal Payments Plugin woocommerce-paypal-payments Broken Access Control Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure No login needed ≤ 4.0.1 CVE-2026-9284 Wordfence
10.0 Critical Gift Cards For WooCommerce Pro Plugin giftware Arbitrary File Upload No login needed ≤ 4.2.6 Fixed in 4.2.7 CVE-2026-45444 Patchstack
7.6 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons SQL Injection ≤ 4.29.0 Fixed in 4.29.1 CVE-2026-42383 Patchstack
7.5 High Creative Mail – Easier WordPress & WooCommerce Email Marketing Plugin creative-mail-by-constant-contact SQL Injection Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uuid' Parameter No login needed ≤ 1.6.9 CVE-2026-3985 Wordfence
7.5 High Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX No login needed < 3.15.0.3 Fixed in 3.15.0.3 CVE-2026-47100 VulnCheck
7.5 High Fortis For WooCommerce Plugin fortis-for-woocommerce Information Disclosure Sensitive API Key Disclosure No login needed < 1.3.1 Fixed in 1.3.1 CVE-2025-15609 WPScan
8.2 High Membership Plugin membership-for-woocommerce SQL Injection WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx No login needed 1.4.7 CVE-2020-37244 VulnCheck
8.1 High FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Broken Access Control Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Configuration Deletion ≤ 1.4.5 CVE-2026-4094 Wordfence
6.1 Medium GLS Shipping for WooCommerce Plugin gls-shipping-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'failed_orders' No login needed ≤ 1.4.0 CVE-2026-6417 Wordfence
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget ≤ 6.4.11 CVE-2026-5243 Wordfence
5.5 Medium Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Cross-Site Scripting WOOF / Products Filter Professional for WooCommerce 1.2.3 Persistent XSS 1.2.3 CVE-2020-37174 VulnCheck
5.5 Medium WPC Badge Management for WooCommerce Plugin wpc-badge-management Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text' Attribute ≤ 3.1.6 CVE-2025-14767 Wordfence
5.3 Medium ilGhera Support System for WooCommerce Plugin wc-support-system Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.3.0 CVE-2025-14033 Wordfence
6.4 Medium Cost of Goods: Product Cost & Profit Calculator for WooCommerce Plugin cost-of-goods-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.0 CVE-2026-6962 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only