WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 451–500 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Broken Access Control ≤ 1.2.150 Fixed in 1.2.151 CVE-2025-64269 Patchstack
4.3 Medium WooCommerce Ultimate Points And Rewards Plugin woocommerce-ultimate-points-and-rewards Information Disclosure Sensitive Data Exposure ≤ 2.10.2 Fixed in 2.10.3 CVE-2025-64267 Patchstack
4.3 Medium Wishlist and Save for later for Woocommerce Plugin aco-wishlist-for-woocommerce Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion ≤ 1.1.22 CVE-2025-12087 Wordfence
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Price Manipulation All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass No login needed ≤ 1.1.27 CVE-2025-12788 Wordfence
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Broken Access Control All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation No login needed ≤ 1.1.27 CVE-2025-12787 Wordfence
5.3 Medium Make Email Customizer for WooCommerce Plugin Broken Access Control Subscriber+ Arbitrary Options Update No login needed ≤ 1.0.6 CVE-2025-11237 WPScan
6.4 Medium Woocommerce – Products By Custom Tax Plugin woocommerce-products-by-custom-tax Cross-Site Scripting Products By Custom Tax <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.2 CVE-2025-11821 Wordfence
4.3 Medium USB Qr Code Scanner For Woocommerce Plugin usb-qr-code-scanner-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.0 CVE-2025-12588 Wordfence
5.3 Medium Flexible Refund and Return Order for WooCommerce Plugin flexible-refund-and-return-order-for-woocommerce Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Refund Status Update No login needed ≤ 1.0.42 CVE-2025-12621 Wordfence
6.5 Medium Bux Woocommerce Plugin bux-woocommerce Broken Access Control No login needed ≤ 1.2.3 CVE-2025-60247 Patchstack
4.3 Medium FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Plugin wp-marketing-automations Broken Access Control Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending ≤ 3.6.4.1 CVE-2025-12469 Wordfence
5.3 Medium FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Plugin wp-marketing-automations Information Disclosure Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure No login needed ≤ 3.6.4.1 CVE-2025-12468 Wordfence
4.3 Medium Import Export For WooCommerce Plugin import-export-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.6.2 CVE-2025-12389 Wordfence
4.3 Medium Smart Coupons for WooCommerce Plugin wt-smart-coupons-for-woocommerce Broken Access Control ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-64358 Patchstack
4.3 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-64290 Patchstack
5.9 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Scripting ≤ 2.2.7 CVE-2025-64289 Patchstack
5.4 Medium Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Broken Access Control ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-64285 Patchstack
5.9 Medium Email Template Customizer for WooCommerce Plugin email-template-customizer-for-woo Cross-Site Scripting ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-64200 Patchstack
5.3 Medium WooCommerce Plugin woocommerce Information Disclosure Sensitive Information Exposure No login needed ≤ 7.8.2 CVE-2023-7320 Wordfence
5.9 Medium WooCommerce Plugin woocommerce Cross-Site Scripting ≤ 10.0.2 Fixed in 10.0.3 CVE-2025-49042 Patchstack
5.3 Medium Facebook for WooCommerce Plugin facebook-for-woocommerce Broken Access Control Broken Access Control to Notice Dismissal No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-64296 Patchstack
4.3 Medium Open Close WooCommerce Store Plugin woc-open-close Broken Access Control ≤ 5.0.0 CVE-2025-62935 Patchstack
5.4 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control ≤ 7.2.13 Fixed in 7.2.14 CVE-2025-62925 Patchstack
6.5 Medium WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Cross-Site Scripting ≤ 4.2.8 Fixed in 4.2.9 CVE-2025-62903 Patchstack
4.3 Medium Premmerce Brands for WooCommerce Plugin premmerce-woocommerce-brands Cross-Site Request Forgery No login needed ≤ 1.2.13 Fixed in 1.2.14 CVE-2025-62890 Patchstack
6.4 Medium The7 — Ultimate WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'the7_fancy_title_css' ≤ 12.9.1 CVE-2025-11897 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.4 CVE-2025-11823 Wordfence
6.1 Medium VNPAY for Woocommerce Plugin vnpay-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-12017 Wordfence
6.4 Medium Simple Excel Pricelist for WooCommerce Plugin simple-excel-pricelist-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.13 CVE-2025-12096 Wordfence
5.8 Medium ShopMagic Plugin shopmagic-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 4.5.6 Fixed in 4.5.7 CVE-2025-59578 Patchstack
6.5 Medium WooCommerce Orders & Customers Exporter Plugin woocommerce-orders-ei Broken Access Control ≤ 5.4 CVE-2025-53424 Patchstack
6.5 Medium SUMO Memberships for WooCommerce Plugin sumomemberships Broken Access Control Arbitrary Content Deletion ≤ 7.8.0 Fixed in 7.8.0 CVE-2025-52757 Patchstack
6.5 Medium WPC Countdown Timer for WooCommerce Plugin wpc-countdown-timer Cross-Site Scripting ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-49908 Patchstack
4.3 Medium Flexible Refund and Return Order for WooCommerce Plugin flexible-refund-and-return-order-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Refund ≤ 1.0.38 CVE-2025-10570 Wordfence
5.3 Medium WPC Smart Quick View for WooCommerce Plugin woo-smart-quick-view Broken Access Control Insecure Direct Object Reference to Unauthenticated Private Product Exposure No login needed ≤ 4.2.5 CVE-2025-11741 Wordfence
4.3 Medium WPC Smart Wishlist for WooCommerce Plugin woo-smart-wishlist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Information Exposure ≤ 5.0.4 CVE-2025-11742 Wordfence
6.4 Medium Stock History & Reports Manager for WooCommerce Plugin stock-snapshot-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.2 CVE-2025-10167 Wordfence
5.3 Medium WPC Smart Wishlist for WooCommerce Plugin woo-smart-wishlist Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed ≤ 5.0.3 CVE-2025-11518 Wordfence
6.4 Medium Big Post Shipping for WooCommerce Plugin woo-bigpost-shipping Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.2 CVE-2025-10191 Wordfence
4.3 Medium Nota Fiscal Eletrônica WooCommerce Plugin nota-fiscal-eletronica-woocommerce Broken Access Control ≤ 3.4.0.9 Fixed in 3.4.1.0 CVE-2025-60159 Patchstack
5.9 Medium Nota Fiscal Eletrônica WooCommerce Plugin nota-fiscal-eletronica-woocommerce Cross-Site Scripting ≤ 3.4.0.9 Fixed in 3.4.1.0 CVE-2025-60158 Patchstack
6.5 Medium Quantities and Units for WooCommerce Plugin quantities-and-units-for-woocommerce Cross-Site Scripting ≤ 1.0.13 CVE-2025-58917 Patchstack
4.3 Medium Payrexx Payment Gateway for WooCommerce Plugin woo-payrexx-gateway Broken Access Control ≤ 3.1.5 Fixed in 3.1.6 CVE-2025-59559 Patchstack
6.5 Medium Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Cross-Site Scripting ≤ 3.0.7 Fixed in 3.0.8 CVE-2025-59565 Patchstack
5.9 Medium CashBill.pl – Płatności WooCommerce Plugin cashbill-payment-method Cross-Site Scripting Płatności WooCommerce Plugin <= 3.2.1 - Cross Site Scripting (XSS) ≤ 3.2.1 Fixed in 3.3.0 CVE-2025-53455 Patchstack
5.9 Medium Sales Count Manager for WooCommerce Plugin wc-sales-count-manager Cross-Site Scripting ≤ 2.6 CVE-2025-57904 Patchstack
5.9 Medium WooCommerce Additional Fees On Checkout (Free) Plugin woo-additional-fees-on-checkout-wordpress Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-57903 Patchstack
4.3 Medium AgreeMe Checkboxes For WooCommerce Plugin agreeme-checkboxes-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-57905 Patchstack
5.9 Medium Product Time Countdown for WooCommerce Plugin product-countdown-for-woocommerce Cross-Site Scripting ≤ 1.6.5 CVE-2025-57908 Patchstack
4.3 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Request Forgery No login needed ≤ 3.0.2 Fixed in 3.1.0 CVE-2025-57914 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only