WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 501–550 of 1,255 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Printcart Web to Print Product Designer for WooCommerce | Broken Access Control |
≤ 2.4.8 |
CVE-2025-57917 |
Patchstack | |
| 5.3 Medium | EnvÃos Coordinadora Woocommerce | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.1.32 |
CVE-2025-57922 |
Patchstack | |
| 6.5 Medium | WPB Quick View for WooCommerce | Cross-Site Scripting |
≤ 2.1.8 Fixed in 2.2 |
CVE-2025-57967 |
Patchstack | |
| 4.3 Medium | Helpdesk Support Ticket System for WooCommerce | Broken Access Control |
≤ 2.1.1 Fixed in 2.1.2 |
CVE-2025-57972 |
Patchstack | |
| 6.5 Medium | Quick View for WooCommerce | Cross-Site Scripting |
≤ 2.2.16 Fixed in 2.2.17 |
CVE-2025-58228 |
Patchstack | |
| 5.3 Medium | TI WooCommerce Wishlist | Broken Access Control No login needed |
≤ 2.10.0 Fixed in 2.11.0 |
CVE-2025-58247 |
Patchstack | |
| 5.3 Medium | Estonian Shipping Methods for WooCommerce | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.7.2 |
CVE-2025-58656 |
Patchstack | |
| 5.3 Medium | Cecabank WooCommerce | Broken Access Control No login needed |
≤ 0.3.4 Fixed in 0.3.5 |
CVE-2025-58685 |
Patchstack | |
| 6.5 Medium | MarketKing | Cross-Site Scripting |
≤ 2.0.92 Fixed in 2.1.00 |
CVE-2025-58702 |
Patchstack | |
| 4.9 Medium | PagBank / PagSeguro Connect para WooCommerce | SQL Injection Authenticated (Shop Manager+) SQL Injection |
≤ 4.44.3 |
CVE-2025-10142 |
Wordfence | |
| 6.5 Medium | Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net | SQL Injection Authenticated (Contributor+) SQL Injection via order_by Parameter |
≤ 1.117.5 |
CVE-2025-9463 |
Wordfence | |
| 6.5 Medium | Additional Custom Product Tabs for WooCommerce | Cross-Site Scripting |
≤ 1.7.3 Fixed in 1.7.4 |
CVE-2025-58985 |
Patchstack | |
| 4.9 Medium | ELEX WooCommerce Google Shopping (Google Product Feed) | SQL Injection Authenticated (Admin+) SQL Inejction |
≤ 1.4.3 |
CVE-2025-10046 |
Wordfence | |
| 6.5 Medium | Woocommerce Gifts Product | Cross-Site Request Forgery No login needed |
≤ 1.0.0 |
CVE-2025-58878 |
Patchstack | |
| 6.5 Medium | Woocommerce Notify Updated Product | Cross-Site Request Forgery No login needed |
≤ 1.6 |
CVE-2025-58856 |
Patchstack | |
| 4.3 Medium | WooCommerce Single Page Checkout | Cross-Site Request Forgery No login needed |
≤ 1.2.7 |
CVE-2025-58804 |
Patchstack | |
| 4.3 Medium | TrustMate.io – WooCommerce integration | Cross-Site Request Forgery WooCommerce integration plugin <= 1.16.0 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.16.0 |
CVE-2025-58802 |
Patchstack | |
| 4.3 Medium | Custom WooCommerce Checkout Fields Editor | Cross-Site Request Forgery No login needed |
≤ 1.3.4 |
CVE-2025-58799 |
Patchstack | |
| 5.3 Medium | PeachPay Payments | Broken Access Control No login needed |
≤ 1.117.4 Fixed in 1.117.5 |
CVE-2025-58634 |
Patchstack | |
| 4.3 Medium | Order Delivery Date for WooCommerce | Broken Access Control |
≤ 4.1.0 Fixed in 4.2.0 |
CVE-2025-58599 |
Patchstack | |
| 6.6 Medium | Klarna Order Management for WooCommerce | Information Disclosure Sensitive Data Exposure |
≤ 1.9.8 Fixed in 1.9.9 |
CVE-2025-58598 |
Patchstack | |
| 5.9 Medium | Risk Free Cash On Delivery (COD) – WooCommerce | Cross-Site Scripting WooCommerce plugin <= 1.0.4 - Cross Site Scripting (XSS) |
≤ 1.0.4 |
CVE-2025-48358 |
Patchstack | |
| 6.4 Medium | Dynamic AJAX Product Filters for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter |
≤ 1.3.7 |
CVE-2025-6255 |
Wordfence | |
| 6.4 Medium | Dynamic AJAX Product Filters for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via name Parameter |
≤ 1.3.7 |
CVE-2025-8073 |
Wordfence | |
| 5.3 Medium | AfterShip Tracking | Broken Access Control No login needed |
≤ 1.17.17 Fixed in 1.17.18 |
CVE-2025-58201 |
Patchstack | |
| 4.3 Medium | Ni WooCommerce Customer Product Report | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 1.2.4 |
CVE-2025-7827 |
Wordfence | |
| 6.4 Medium | WPC Smart Quick View for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woosq_btn Shortcode |
≤ 4.2.1 |
CVE-2025-8618 |
Wordfence | |
| 6.4 Medium | WPC Smart Compare for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 6.4.7 |
CVE-2025-7496 |
Wordfence | |
| 6.6 Medium | Woocommerce Blocks – Woolook | Local File Inclusion Woolook <= 1.7.0 - Authenticated (Admin+) Local File Inclusion |
≤ 1.7.0 |
CVE-2024-8393 |
Wordfence | |
| 4.3 Medium | YITH WooCommerce Popup | Cross-Site Request Forgery No login needed |
≤ 1.48.0 Fixed in 1.48.1 |
CVE-2025-54675 |
Patchstack | |
| 5.4 Medium | Product Configurator for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 1.4.4 Fixed in 1.5.0 |
CVE-2025-54674 |
Patchstack | |
| 6.5 Medium | Thank You Page Customizer for WooCommerce | Broken Access Control Increase Your Sales <= 1.1.7 - Broken Access Control |
≤ 1.1.7 Fixed in 1.1.8 |
CVE-2025-30993 |
Patchstack | |
| 6.5 Medium | WooCommerce Fortnox Integration | Cross-Site Scripting |
≤ 4.5.6 Fixed in 4.5.7 |
CVE-2025-47610 |
Patchstack | |
| 5.3 Medium | FiboSearch | Broken Access Control No login needed |
≤ 1.32.1 Fixed in 1.32.2 |
CVE-2025-47444 |
Patchstack | |
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.3.10 |
CVE-2025-7646 |
Wordfence | |
| 6.4 Medium | Customer Reviews for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via `author` Parameter |
≤ 5.80.2 |
CVE-2025-5720 |
Wordfence | |
| 4.3 Medium | Bonanza – WooCommerce Free Gifts Lite | Broken Access Control WooCommerce Free Gifts Lite <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Opt In Success |
≤ 1.0.0 |
CVE-2025-6730 |
Wordfence | |
| 5.3 Medium | WoodMart - Multipurpose WooCommerce | Broken Access Control Multipurpose WooCommerce Theme <= 8.2.6 - Improper Input Validation Leading to Unauthenticated Cart Manipulation No login needed |
≤ 8.2.6 |
CVE-2025-8097 |
Wordfence | |
| 6.5 Medium | B1.lt for WooCommerce | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 2.2.56 |
CVE-2025-6717 |
Wordfence | |
| 6.4 Medium | Crowdfunding for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter |
≤ 3.1.14 |
CVE-2025-5767 |
Wordfence | |
| 4.3 Medium | Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship | Broken Access Control Biteship <= 3.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) View Order Tracking Details |
≤ 3.2.0 |
CVE-2025-5816 |
Wordfence | |
| 6.5 Medium | Product XML Feed Manager for WooCommerce | Broken Access Control No login needed |
≤ 2.9.2 Fixed in 2.9.3 |
CVE-2025-30959 |
Patchstack | |
| 6.5 Medium | Wishlist for WooCommerce | Broken Access Control No login needed |
≤ 3.2.3 Fixed in 3.2.4 |
CVE-2025-49319 |
Patchstack | |
| 4.3 Medium | Wallet System for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 2.6.7 Fixed in 2.6.8 |
CVE-2025-54041 |
Patchstack | |
| 4.3 Medium | WooCommerce Google Sheet Connector | Cross-Site Request Forgery No login needed |
≤ 1.3.20 Fixed in 1.4.0 |
CVE-2025-54030 |
Patchstack | |
| 6.4 Medium | WPC Smart Compare for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.4.6 |
CVE-2025-5530 |
Wordfence | |
| 4.3 Medium | Order Delivery Date Pro for WooCommerce | Information Disclosure Unauthenticated Arbitrary Post Title Disclosure No login needed |
2.0 – < 12.6.0 Fixed in 12.6.0 |
CVE-2025-2942 |
WPScan | |
| 6.5 Medium | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification No login needed |
≤ 6.7.16 |
CVE-2025-3780 |
Wordfence | |
| 6.5 Medium | Paytiko for WooCommerce | Broken Access Control |
≤ 1.3.21 |
CVE-2025-50032 |
Patchstack | |
| 4.3 Medium | WooCommerce Shop Page Builder | Broken Access Control |
≤ 2.27.7 |
CVE-2025-29001 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.