WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 451–500 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Product Import Export for WooCommerce Plugin product-import-export-for-woo PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.5.0 CVE-2025-1913 Wordfence
7.6 High Product Import Export for WooCommerce Plugin product-import-export-for-woo Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.5.0 CVE-2025-1912 Wordfence
7.3 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Broken Access Control Unauthenticated Arbitrary Filter Call No login needed ≤ 1.0.6.7 CVE-2025-1514 Wordfence
7.5 High Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit Plugin wp-marketing-automations SQL Injection Unauthenticated SQL Injection via 'automationId' No login needed ≤ 3.5.1 CVE-2025-2186 Wordfence
7.6 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.2 CVE-2025-1970 Wordfence
7.2 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.6.2 CVE-2025-1971 Wordfence
7.2 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.6.0 CVE-2024-13921 Wordfence
7.5 High NP Quote Request for WooCommerce Plugin woo-rfq-for-woocommerce Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure No login needed ≤ 1.9.179 CVE-2024-13558 Wordfence
7.6 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.0 CVE-2024-13923 Wordfence
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-26921 Patchstack
7.1 High Pre Order Addon for WooCommerce – Advance Order/Backorder Plugin wc-pre-order Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2 CVE-2025-26553 Patchstack
7.5 High WC Place Order Without Payment Plugin wc-place-order-without-payment Local File Inclusion No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-26933 Patchstack
8.1 High Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 1.12.0 CVE-2024-13359 Wordfence
7.5 High CURCY - WooCommerce Multi Currency - Currency Switcher Plugin SQL Injection WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection No login needed ≤ 2.3.6 CVE-2024-13320 Wordfence
8.1 High WooCommerce Recover Abandoned Cart Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 24.4.0 CVE-2025-0956 Wordfence
7.1 High SMS Alert Order Notifications Plugin sms-alert Cross-Site Scripting WooCommerce plugin <= 3.7.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26984 Patchstack
7.1 High Woocommerce osCommerce Sync Plugin woo-oscommerce-sync Cross-Site Scripting No login needed ≤ 2.0.20 CVE-2025-25119 Patchstack
7.1 High Local Shipping Labels for WooCommerce Plugin local-shipping-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23903 Patchstack
7.1 High Tax Report for WooCommerce Plugin tax-report-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-23731 Patchstack
7.1 High ChatGPT Open AI Images & Content for WooCommerce Plugin glasses-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2025-23668 Patchstack
7.1 High Ni WooCommerce Sales Report Email Plugin ni-woocommerce-sales-report-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.4 CVE-2025-23481 Patchstack
7.1 High AW WooCommerce Kode Pembayaran Plugin aw-woocommerce-kode-pembayaran Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.4 CVE-2025-23450 Patchstack
7.2 High Tabs for WooCommerce Plugin wc-tabs PHP Object Injection Authentiated (Shop Manager+) PHP Object Injection in product_has_custom_tabs ≤ 1.0.0 CVE-2024-13831 Wordfence
7.1 High Woocommerce – Loi Hamon Plugin loi-hamon Cross-Site Request Forgery Loi Hamon Plugin <= 1.1.0 - CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-27355 Patchstack
7.1 High WooCommerce Pricing – Product Pricing Plugin woo-pricing-table Cross-Site Scripting Product Pricing plugin <= 1.0.9 - Cross Site Scripting (XSS) No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-22632 Patchstack
8.8 High A1POST.BG Shipping for Woo Plugin a1post-bg-shipping-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.5 Fixed in 1.5.1 CVE-2025-27012 Patchstack
7.3 High WooCommerce Food - Restaurant Menu & Food ordering Plugin Arbitrary Shortcode Execution Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids No login needed ≤ 3.3.2 CVE-2024-13792 Wordfence
8.5 High Distance Rate Shipping for WooCommerce Plugin distance-rate-shipping-for-woocommerce-pro SQL Injection ≤ 1.3.4 CVE-2025-22639 Patchstack
7.3 High PressMart - Modern Elementor WooCommerce Theme Arbitrary Shortcode Execution Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.16 CVE-2024-13797 Wordfence
8.8 High Shopwarden – Automated WooCommerce monitoring & testing Plugin shopwarden Cross-Site Request Forgery Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.0.11 CVE-2024-13315 Wordfence
7.5 High File Uploads Addon for WooCommerce Plugin woo-addon-uploads Arbitrary File Upload Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 1.7.1 CVE-2024-13622 Wordfence
7.1 High Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.22 Fixed in 2.9.0 CVE-2025-24592 Patchstack
7.1 High URL Shortener | Conversion Tracking | AB Testing | WooCommerce Plugin easy-broken-link-checker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.0.2 CVE-2025-23789 Patchstack
7.5 High Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Authentication Bypass Authentication Bypass via Shortcode ≤ 2.9.5 CVE-2024-13528 Wordfence
7.3 High CURCY – Multi Currency for WooCommerce Plugin woo-multi-currency Arbitrary Shortcode Execution Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function No login needed ≤ 2.2.5 CVE-2024-13487 Wordfence
8.8 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager PHP Object Injection ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-24661 Patchstack
7.1 High PeproDev WooCommerce Receipt Uploader Plugin pepro-bacs-receipt-upload-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-24574 Patchstack
8.8 High WooCommerce Customers Manager Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 31.3 CVE-2024-13343 Wordfence
7.3 High WooCommerce Product Table Lite Plugin wc-product-table-lite Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed ≤ 3.9.4 CVE-2024-13472 Wordfence
7.1 High Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Cross-Site Scripting WordPress Advanced Dynamic Pricing for WooCommerce Plugin <= 4.9.0 -Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.0 Fixed in 4.9.1 CVE-2025-24632 Patchstack
7.1 High PORTONE 우커머스 결제 Plugin iamport-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.4 Fixed in 3.2.6 CVE-2025-24609 Patchstack
7.1 High Radio Buttons and Swatches for WooCommerce Plugin variations-radio-buttons-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.20 Fixed in 1.1.21 CVE-2025-24551 Patchstack
8.8 High MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Plugin makewebbetter-hubspot-for-woocommerce Broken Access Control CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics <= 1.5.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update ≤ 1.5.9 CVE-2024-10591 Wordfence
7.5 High WooCommerce Wishlist Plugin smart-wishlist-for-more-convert Information Disclosure Unauthenticated Wishlist Disclosure via download_pdf_file Function No login needed ≤ 1.8.7 CVE-2024-13694 Wordfence
7.2 High Flexible Wishlist for WooCommerce Plugin flexible-wishlist Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via wishlist_name Parameter No login needed ≤ 1.2.25 CVE-2024-13696 Wordfence
7.2 High Custom Product Tabs Lite for WooCommerce Plugin woocommerce-custom-product-tabs-lite PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.9.0 CVE-2024-12600 Wordfence
7.1 High a Gateway for Pasargad Bank on WooCommerce Plugin a-gateway-for-pasargad-bank-on-woocommerce Cross-Site Scripting No login needed ≤ 2.5.2 CVE-2025-23966 Patchstack
7.1 High WooCommerce Order Search Plugin woocommerce-order-searching Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-23495 Patchstack
7.5 High Standard Box Sizes – for WooCommerce Plugin standard-box-sizes Broken Access Control No login needed ≤ 1.6.13 Fixed in 1.6.14 CVE-2025-22318 Patchstack
7.1 High EditionGuard for WooCommerce – eBook Sales with DRM Plugin editionguard-for-woocommerce-ebook-sales-with-drm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2 CVE-2025-23452 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only