WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 451–500 of 1,255 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | WooCommerce PDF Invoice Builder | Broken Access Control |
≤ 1.2.150 Fixed in 1.2.151 |
CVE-2025-64269 |
Patchstack | |
| 4.3 Medium | WooCommerce Ultimate Points And Rewards | Information Disclosure Sensitive Data Exposure |
≤ 2.10.2 Fixed in 2.10.3 |
CVE-2025-64267 |
Patchstack | |
| 4.3 Medium | Wishlist and Save for later for Woocommerce | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion |
≤ 1.1.22 |
CVE-2025-12087 |
Wordfence | |
| 5.3 Medium | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings | Price Manipulation All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass No login needed |
≤ 1.1.27 |
CVE-2025-12788 |
Wordfence | |
| 5.3 Medium | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings | Broken Access Control All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation No login needed |
≤ 1.1.27 |
CVE-2025-12787 |
Wordfence | |
| 5.3 Medium | Make Email Customizer for WooCommerce | Broken Access Control Subscriber+ Arbitrary Options Update No login needed |
≤ 1.0.6 |
CVE-2025-11237 |
WPScan | |
| 6.4 Medium | Woocommerce – Products By Custom Tax | Cross-Site Scripting Products By Custom Tax <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.2 |
CVE-2025-11821 |
Wordfence | |
| 4.3 Medium | USB Qr Code Scanner For Woocommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.0 |
CVE-2025-12588 |
Wordfence | |
| 5.3 Medium | Flexible Refund and Return Order for WooCommerce | Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Refund Status Update No login needed |
≤ 1.0.42 |
CVE-2025-12621 |
Wordfence | |
| 6.5 Medium | Bux Woocommerce | Broken Access Control No login needed |
≤ 1.2.3 |
CVE-2025-60247 |
Patchstack | |
| 4.3 Medium | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Broken Access Control Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending |
≤ 3.6.4.1 |
CVE-2025-12469 |
Wordfence | |
| 5.3 Medium | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Information Disclosure Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure No login needed |
≤ 3.6.4.1 |
CVE-2025-12468 |
Wordfence | |
| 4.3 Medium | Import Export For WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 1.6.2 |
CVE-2025-12389 |
Wordfence | |
| 4.3 Medium | Smart Coupons for WooCommerce | Broken Access Control |
≤ 2.2.3 Fixed in 2.2.4 |
CVE-2025-64358 |
Patchstack | |
| 4.3 Medium | Premmerce Product Search for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 2.2.4 Fixed in 2.2.5 |
CVE-2025-64290 |
Patchstack | |
| 5.9 Medium | Premmerce Product Search for WooCommerce | Cross-Site Scripting |
≤ 2.2.7 |
CVE-2025-64289 |
Patchstack | |
| 5.4 Medium | Premmerce Wholesale Pricing for WooCommerce | Broken Access Control |
≤ 1.1.10 Fixed in 1.1.11 |
CVE-2025-64285 |
Patchstack | |
| 5.9 Medium | Email Template Customizer for WooCommerce | Cross-Site Scripting |
≤ 1.2.17 Fixed in 1.2.18 |
CVE-2025-64200 |
Patchstack | |
| 5.3 Medium | WooCommerce | Information Disclosure Sensitive Information Exposure No login needed |
≤ 7.8.2 |
CVE-2023-7320 |
Wordfence | |
| 5.9 Medium | WooCommerce | Cross-Site Scripting |
≤ 10.0.2 Fixed in 10.0.3 |
CVE-2025-49042 |
Patchstack | |
| 5.3 Medium | Facebook for WooCommerce | Broken Access Control Broken Access Control to Notice Dismissal No login needed |
≤ 3.5.7 Fixed in 3.5.8 |
CVE-2025-64296 |
Patchstack | |
| 4.3 Medium | Open Close WooCommerce Store | Broken Access Control |
≤ 5.0.0 |
CVE-2025-62935 |
Patchstack | |
| 5.4 Medium | Conversios.io | Broken Access Control |
≤ 7.2.13 Fixed in 7.2.14 |
CVE-2025-62925 |
Patchstack | |
| 6.5 Medium | WPC Smart Messages for WooCommerce | Cross-Site Scripting |
≤ 4.2.8 Fixed in 4.2.9 |
CVE-2025-62903 |
Patchstack | |
| 4.3 Medium | Premmerce Brands for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 1.2.13 Fixed in 1.2.14 |
CVE-2025-62890 |
Patchstack | |
| 6.4 Medium | The7 — Ultimate WordPress & WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'the7_fancy_title_css' |
≤ 12.9.1 |
CVE-2025-11897 |
Wordfence | |
| 6.4 Medium | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.2.4 |
CVE-2025-11823 |
Wordfence | |
| 6.1 Medium | VNPAY for Woocommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.0 |
CVE-2025-12017 |
Wordfence | |
| 6.4 Medium | Simple Excel Pricelist for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.13 |
CVE-2025-12096 |
Wordfence | |
| 5.8 Medium | ShopMagic | Information Disclosure Sensitive Data Exposure No login needed |
≤ 4.5.6 Fixed in 4.5.7 |
CVE-2025-59578 |
Patchstack | |
| 6.5 Medium | WooCommerce Orders & Customers Exporter | Broken Access Control |
≤ 5.4 |
CVE-2025-53424 |
Patchstack | |
| 6.5 Medium | SUMO Memberships for WooCommerce | Broken Access Control Arbitrary Content Deletion |
≤ 7.8.0 Fixed in 7.8.0 |
CVE-2025-52757 |
Patchstack | |
| 6.5 Medium | WPC Countdown Timer for WooCommerce | Cross-Site Scripting |
≤ 3.1.4 Fixed in 3.1.5 |
CVE-2025-49908 |
Patchstack | |
| 4.3 Medium | Flexible Refund and Return Order for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Refund |
≤ 1.0.38 |
CVE-2025-10570 |
Wordfence | |
| 5.3 Medium | WPC Smart Quick View for WooCommerce | Broken Access Control Insecure Direct Object Reference to Unauthenticated Private Product Exposure No login needed |
≤ 4.2.5 |
CVE-2025-11741 |
Wordfence | |
| 4.3 Medium | WPC Smart Wishlist for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Information Exposure |
≤ 5.0.4 |
CVE-2025-11742 |
Wordfence | |
| 6.4 Medium | Stock History & Reports Manager for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.2 |
CVE-2025-10167 |
Wordfence | |
| 5.3 Medium | WPC Smart Wishlist for WooCommerce | Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed |
≤ 5.0.3 |
CVE-2025-11518 |
Wordfence | |
| 6.4 Medium | Big Post Shipping for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.1.2 |
CVE-2025-10191 |
Wordfence | |
| 4.3 Medium | Nota Fiscal Eletrônica WooCommerce | Broken Access Control |
≤ 3.4.0.9 Fixed in 3.4.1.0 |
CVE-2025-60159 |
Patchstack | |
| 5.9 Medium | Nota Fiscal Eletrônica WooCommerce | Cross-Site Scripting |
≤ 3.4.0.9 Fixed in 3.4.1.0 |
CVE-2025-60158 |
Patchstack | |
| 6.5 Medium | Quantities and Units for WooCommerce | Cross-Site Scripting |
≤ 1.0.13 |
CVE-2025-58917 |
Patchstack | |
| 4.3 Medium | Payrexx Payment Gateway for WooCommerce | Broken Access Control |
≤ 3.1.5 Fixed in 3.1.6 |
CVE-2025-59559 |
Patchstack | |
| 6.5 Medium | Upsell Order Bump Offer for WooCommerce | Cross-Site Scripting |
≤ 3.0.7 Fixed in 3.0.8 |
CVE-2025-59565 |
Patchstack | |
| 5.9 Medium | CashBill.pl – Płatności WooCommerce | Cross-Site Scripting Płatności WooCommerce Plugin <= 3.2.1 - Cross Site Scripting (XSS) |
≤ 3.2.1 Fixed in 3.3.0 |
CVE-2025-53455 |
Patchstack | |
| 5.9 Medium | Sales Count Manager for WooCommerce | Cross-Site Scripting |
≤ 2.6 |
CVE-2025-57904 |
Patchstack | |
| 5.9 Medium | WooCommerce Additional Fees On Checkout (Free) | Cross-Site Scripting |
≤ 1.5.2 Fixed in 1.5.3 |
CVE-2025-57903 |
Patchstack | |
| 4.3 Medium | AgreeMe Checkboxes For WooCommerce | Cross-Site Request Forgery No login needed |
≤ 1.1.3 |
CVE-2025-57905 |
Patchstack | |
| 5.9 Medium | Product Time Countdown for WooCommerce | Cross-Site Scripting |
≤ 1.6.5 |
CVE-2025-57908 |
Patchstack | |
| 4.3 Medium | Deliver via Shipos for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 3.0.2 Fixed in 3.1.0 |
CVE-2025-57914 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.