WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 501–550 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High APIExperts Square for WooCommerce Plugin woosquare SQL Injection ≤ 4.7.1 Fixed in 4.7.2 CVE-2026-45211 Patchstack
5.3 Medium Slek Gateway for WooCommerce Plugin slek-gateway-for-woocommerce Information Disclosure Unauthenticated Insufficiently Protected Credentials via Payment Redirect Form Hidden Fields No login needed ≤ 1.0 CVE-2026-7626 Wordfence
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.12.0 Fixed in 4.13.0 CVE-2026-27329 Patchstack
5.3 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Broken Access Control Missing Authorization to Unauthenticated PIX Payment QR Code Image Disclosure No login needed ≤ 8.7.11 CVE-2026-3208 Wordfence
6.4 Medium NextMove Lite - Thank You Page for WooCommerce Plugin woo-thank-you-page-nextmove-lite Cross-Site Scripting Thank You Page for WooCommerce <= 2.23.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'xlwcty_current_date' Shortcode ≤ 2.23.0 CVE-2026-0703 Wordfence
5.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Information Disclosure Unauthenticated Information Disclosure in Store Reviews REST API Endpoint No login needed ≤ 4.3.1 CVE-2026-3504 Wordfence
8.1 High WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion ≤ 6.7.25 CVE-2026-2554 Wordfence
4.4 Medium Call for Price for WooCommerce Plugin woocommerce-call-for-price Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Call for Price' Label Settings ≤ 4.2.0 CVE-2026-6447 Wordfence
6.4 Medium WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute ≤ 4.2.8 CVE-2026-6725 Wordfence
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-28040 Patchstack
4.3 Medium Ni WooCommerce Order Export Plugin ni-woocommerce-order-export Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update via ni_order_export_action AJAX Action No login needed ≤ 3.1.6 CVE-2026-4140 Wordfence
6.1 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'crsearch' No login needed ≤ 5.101.0 CVE-2026-3355 Wordfence
7.5 High Payment Gateway for Redsys & WooCommerce Lite Plugin woo-redsys-gateway-light Other Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation No login needed ≤ 7.0.0 CVE-2026-5050 Wordfence
7.5 High Accept Cryptocurrencies with Plisio Plugin plisio-payment-gateway-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 2.0.5 CVE-2026-6372 Patchstack
5.9 Medium Mini Ajax Cart for WooCommerce Plugin mini-ajax-woo-cart Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-6370 Patchstack
6.5 Medium Germanized for WooCommerce Plugin woocommerce-germanized Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.20.5 CVE-2026-2582 Wordfence
4.4 Medium WholeSale Products Dynamic Pricing Management WooCommerce Plugin wholesale-products-dynamic-pricing-management-woocommerce Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.2 CVE-2026-4479 Wordfence
8.6 High Product Filter for WooCommerce by WBW Plugin woo-product-filter SQL Injection Unauthenticated SQLi No login needed < 3.1.3 Fixed in 3.1.3 CVE-2026-3830 WPScan
6.5 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Unauthenticated Arbitrary Wishlist Renaming via IDOR No login needed < 4.13.0 Fixed in 4.13.0 CVE-2026-4432 WPScan
5.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Authentication Bypass Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' Parameter No login needed ≤ 5.103.0 CVE-2026-4664 Wordfence
4.4 Medium Experto Dashboard for WooCommerce Plugin experto-custom-dashboard Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Navigation Font Size' Setting ≤ 1.0.4 CVE-2026-3574 Wordfence
7.5 High WCAPF – WooCommerce Ajax Product Filter Plugin wc-ajax-product-filter SQL Injection WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection No login needed ≤ 4.2.3 CVE-2026-3396 Wordfence
6.5 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Product Data Modification No login needed ≤ 1.1.5 CVE-2026-1672 Wordfence
4.3 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Taxonomy Term Deletion No login needed ≤ 1.1.5 CVE-2026-1673 Wordfence
7.1 High Extra Fees Plugin for WooCommerce Plugin woo-conditional-product-fees-for-checkout Cross-Site Request Forgery No login needed ≤ 4.3.3 CVE-2026-39671 Patchstack
5.3 Medium Book Previewer for Woocommerce Plugin book-previewer-for-woocommerce Broken Access Control No login needed ≤ 1.0.6 CVE-2026-39668 Patchstack
5.3 Medium Product Price by Formula for WooCommerce Plugin product-price-by-formula-for-woocommerce Broken Access Control No login needed ≤ 2.5.6 CVE-2026-39662 Patchstack
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control No login needed ≤ 4.8.2 CVE-2026-39656 Patchstack
5.4 Medium GlobalPayments WooCommerce Plugin global-payments-woocommerce Server-Side Request Forgery No login needed ≤ 1.18.0 CVE-2026-39645 Patchstack
5.3 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Broken Access Control No login needed ≤ 2.0.13 CVE-2026-39643 Patchstack
5.3 Medium Doofinder for WooCommerce Plugin doofinder-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 2.10.13 Fixed in 2.10.14 CVE-2026-39542 Patchstack
6.5 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Cross-Site Scripting ≤ 4.7.1.1 Fixed in 4.7.2 CVE-2026-39508 Patchstack
5.3 Medium FOX Plugin woocommerce-currency-switcher Broken Access Control No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-39501 Patchstack
7.6 High FOX Plugin woocommerce-currency-switcher SQL Injection ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-39497 Patchstack
4.4 Medium Whole Enquiry Cart for WooCommerce Plugin whole-cart-enquiry Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'woowhole_success_msg' Parameter ≤ 1.2.1 CVE-2026-2838 Wordfence
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar ≤ 6.4.9 CVE-2026-3311 Wordfence
8.8 High Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce Plugin woo-product-feed-pro Cross-Site Request Forgery Product Feeds for WooCommerce 13.4.6 - 13.5.2.1 - Cross-Site Request Forgery to Multiple Administrative Actions No login needed 13.4.6 – 13.5.2.1 CVE-2026-3499 Wordfence
8.1 High WCFM - WooCommerce Frontend Manager Plugin wc-frontend-manager Broken Access Control WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation ≤ 6.7.25 CVE-2026-4896 Wordfence
9.1 Critical Order Notification for WooCommerce Plugin Authentication Bypass Unauthenticated WooCommerce REST Permission Bypass No login needed < 3.6.3 Fixed in 3.6.3 CVE-2025-15484 WPScan
6.5 Medium WooPayments Plugin woocommerce-payments Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajax No login needed ≤ 10.5.1 CVE-2026-1710 Wordfence
7.1 High Riode Plugin riode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ < 1.6.29 Fixed in 1.6.29 CVE-2026-32528 Patchstack
7.1 High Abandoned Cart Recovery for WooCommerce Plugin woo-abandoned-cart-recovery Cross-Site Scripting No login needed ≤ <= 1.1.10 Fixed in 1.1.11 CVE-2026-32526 Patchstack
8.6 High WooCommerce Support Ticket System Plugin woocommerce-support-ticket-system Arbitrary File Deletion No login needed ≤ < 18.5 Fixed in 18.5 CVE-2026-32522 Patchstack
7.7 High Comments Import & Export Plugin comments-import-export-woocommerce Broken Access Control ≤ <= 2.4.9 Fixed in 2.5.0 CVE-2026-32441 Patchstack
8.2 High Product Rearrange for WooCommerce Plugin products-rearrange-woocommerce Broken Access Control No login needed ≤ <= 1.2.2 CVE-2026-31921 Patchstack
9.3 Critical Product Rearrange for WooCommerce Plugin products-rearrange-woocommerce SQL Injection No login needed ≤ <= 1.2.2 CVE-2026-31920 Patchstack
8.8 High WooCommerce Infinite Scroll Plugin sb-woocommerce-infinite-scroll PHP Object Injection ≤ 1.6.2 CVE-2026-27045 Patchstack
6.5 Medium ViaBill – WooCommerce Plugin viabill-woocommerce Broken Access Control WooCommerce plugin <= 1.1.53 - Settings Change No login needed ≤ 1.1.53 CVE-2026-25469 Patchstack
6.5 Medium Product Slider for WooCommerce Plugin woocommerce-products-slider Broken Access Control ≤ 1.13.61 Fixed in 1.13.62 CVE-2026-25455 Patchstack
7.5 High File Uploader for WooCommerce Plugin file-uploader-for-woocommerce Arbitrary File Upload Path Traversal No login needed ≤ 1.0.4 CVE-2026-25397 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only