WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 501–550 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Altima Lookbook Free for WooCommerce Plugin altima-lookbook-free-for-woocommerce Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-23429 Patchstack
8.5 High Neon Product Designer Plugin neon-product-designer-for-woocommerce SQL Injection ≤ 2.2.0 CVE-2025-22799 Patchstack
7.1 High Order Audit Log for WooCommerce Plugin order-audit-log-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-22337 Patchstack
7.1 High Scanventory Plugin woocommerce-inventory-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2025-22588 Patchstack
7.5 High Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups Plugin coupon-x-discount-pop-up Broken Access Control Missing Authorization to Authenticated (Contributor+) PHP Object Injection ≤ 1.3.5 CVE-2024-12627 Wordfence
7.1 High Product Table for WooCommerce Plugin woo-product-table Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.3 Fixed in 5.0.0 CVE-2025-22307 Patchstack
8.5 High NC Wishlist for Woocommerce Plugin nc-wishlist-for-woocommerce SQL Injection ≤ 1.0.1 CVE-2025-22505 Patchstack
7.5 High Ultimate Gift Cards for WooCommerce Plugin woo-gift-cards-lite Broken Access Control Missing Authorization to Infinite Money Glitch No login needed ≤ 2.9.1, ≤ 3.0.6 CVE-2024-11423 Wordfence
7.5 High 워드프레스 결제 심플페이 Plugin pgall-for-woocommerce Local File Inclusion 우커머스 결제 플러그인 plugin <= 5.2.0 - Local File Inclusion ≤ 5.2.0 Fixed in 5.2.2 CVE-2024-56281 Patchstack
7.6 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-22352 Patchstack
8.8 High SMS Alert Order Notifications – WooCommerce Plugin sms-alert Broken Access Control WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.7.6 CVE-2024-11725 Wordfence
8.1 High Compare Products for WooCommerce Plugin woocommerce-compare-products PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.2.1 CVE-2024-12313 Wordfence
7.2 High Custom Product Tabs for WooCommerce Plugin yikes-inc-easy-custom-woocommerce-product-tabs PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.8.5 CVE-2024-11465 Wordfence
8.8 High EditionGuard for WooCommerce – eBook Sales with DRM Plugin editionguard-for-woocommerce-ebook-sales-with-drm Cross-Site Request Forgery eBook Sales with DRM plugin <= 3.4.2 - CSRF to Privilege Escalation No login needed ≤ 3.4.2 CVE-2024-56207 Patchstack
7.1 High Wishlist for WooCommerce Plugin wish-list-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-56228 Patchstack
7.1 High WooCommerce PDF Vouchers Plugin woocommerce-pdf-vouchers Cross-Site Scripting PDF Vouchers plugin < 4.9.9 - Cross Site Scripting (XSS) No login needed ≤ 4.9.9 Fixed in 4.9.9 CVE-2024-56265 Patchstack
7.5 High Dynamic Product Category Grid, Slider for WooCommerce Plugin dynamic-product-categories-design Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-56230 Patchstack
7.2 High Custom Product Tabs For WooCommerce Plugin wb-custom-product-tabs-for-woocommerce PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.2.4 CVE-2024-12721 Wordfence
7.5 High Spreadr Woocommerce Plugin spreadr-for-woocomerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-56008 Patchstack
8.1 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer Authentication Bypass Authentication Bypass Due to Insufficiently Unique Key No login needed ≤ 1.2.8 CVE-2024-12432 Wordfence
7.1 High Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart Plugin push-monkey-desktop-push-notifications Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.9 CVE-2024-54386 Patchstack
7.1 High Check Pincode For Woocommerce Plugin check-pincode-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 Fixed in 1.2 CVE-2024-54333 Patchstack
7.1 High Invoice Payment for WooCommerce Plugin invoice-payment-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.2 Fixed in 2.0.0 CVE-2024-54328 Patchstack
7.1 High Persian Woocommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.0.5 Fixed in 7.0.6 CVE-2024-54312 Patchstack
7.1 High Blaze Online eParcel for WooCommerce Plugin blaze-online-eparcel-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2024-54240 Patchstack
7.1 High Ni WooCommerce Bulk Product Editor Plugin ni-woocommerce-product-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2024-54236 Patchstack
7.1 High Shiptimize for WooCommerce Plugin shiptimize-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.86 CVE-2024-54235 Patchstack
7.1 High Ni WooCommerce Order Export Plugin ni-woocommerce-order-export Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.6 CVE-2024-54231 Patchstack
8.8 High Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' ≤ 1.9.10 CVE-2024-12040 Wordfence
7.3 High Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed ≤ 1.0.6.5 CVE-2024-10959 Wordfence
8.6 High Japanized For WooCommerce Plugin woocommerce-for-japan Broken Access Control Multiple Broken Access Control No login needed ≤ 2.6.4 Fixed in 2.6.5 CVE-2023-47698 Patchstack
8.2 High Flexible Woocommerce Checkout Field Editor Plugin flexible-woocommerce-checkout-field-editor Broken Access Control No login needed ≤ 2.0.1 CVE-2023-49817 Patchstack
8.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.0.23 Fixed in 4.0.24 CVE-2023-51355 Patchstack
7.6 High Product Labels For Woocommerce Plugin aco-product-labels-for-woocommerce SQL Injection ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-53817 Patchstack
7.5 High TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control Missing Authorization to Unauthenticated Plugin Setup Wizard Access No login needed ≤ 2.9.1 CVE-2024-10567 Wordfence
7.1 High AtaraPay WooCommerce Payment Gateway Plugin atarapay-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.13 CVE-2024-52460 Patchstack
7.1 High WooCommerce Price Alert Plugin price-alert-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2024-52469 Patchstack
7.1 High WooCommerce Ultimate Gift Card Plugin woocommerce-ultimate-gift-card Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.1 Fixed in 2.9.1 CVE-2024-53740 Patchstack
7.1 High Multilevel Referral Affiliate Plugin for WooCommerce Plugin multilevel-referral-plugin-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.27 Fixed in 2.28 CVE-2024-53742 Patchstack
7.6 High Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods SQL Injection ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-53783 Patchstack
8.8 High Booking & Appointment Plugin for WooCommerce Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 6.9.0 CVE-2024-10729 Wordfence
7.3 High Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation Plugin get-a-quote-button-for-woocommerce Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed ≤ 1.4 CVE-2024-11034 Wordfence
7.3 High WooCommerce Product Table Lite Plugin wc-product-table-lite Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed ≤ 3.8.6 CVE-2024-10899 Wordfence
8.0 High Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation ≤ 6.0.9 CVE-2024-8979 Wordfence
8.1 High Advanced Order Export For WooCommerce Plugin woo-order-export-lite PHP Object Injection Unauthenticated PHP Object Injection via Order Details No login needed ≤ 3.5.5 CVE-2024-10828 Wordfence
7.1 High Search order by product SKU for WooCommerce Plugin search-order-by-product-sku-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2024-51693 Patchstack
7.3 High The FOX – Currency Switcher Professional for WooCommerce Plugin Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.2.2 CVE-2024-10640 Wordfence
7.1 High FriendStore for WooCommerce Plugin friendstore-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.2 CVE-2024-51784 Patchstack
8.8 High WooCommerce Support Ticket System Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 17.7 CVE-2024-10626 Wordfence
8.8 High WooCommerce Report Plugin ithemelandco-woo-report Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.5.1 CVE-2024-10711 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only