WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 501–550 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration Broken Access Control ≤ 2.4.8 CVE-2025-57917 Patchstack
5.3 Medium Envíos Coordinadora Woocommerce Plugin coordinadora Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.32 CVE-2025-57922 Patchstack
6.5 Medium WPB Quick View for WooCommerce Plugin woocommerce-lightbox Cross-Site Scripting ≤ 2.1.8 Fixed in 2.2 CVE-2025-57967 Patchstack
4.3 Medium Helpdesk Support Ticket System for WooCommerce Plugin support-ticket-system-for-woocommerce Broken Access Control ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-57972 Patchstack
6.5 Medium Quick View for WooCommerce Plugin woo-quickview Cross-Site Scripting ≤ 2.2.16 Fixed in 2.2.17 CVE-2025-58228 Patchstack
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control No login needed ≤ 2.10.0 Fixed in 2.11.0 CVE-2025-58247 Patchstack
5.3 Medium Estonian Shipping Methods for WooCommerce Plugin estonian-shipping-methods-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 1.7.2 CVE-2025-58656 Patchstack
5.3 Medium Cecabank WooCommerce Plugin cecabank-woocommerce Broken Access Control No login needed ≤ 0.3.4 Fixed in 0.3.5 CVE-2025-58685 Patchstack
6.5 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Cross-Site Scripting ≤ 2.0.92 Fixed in 2.1.00 CVE-2025-58702 Patchstack
4.9 Medium PagBank / PagSeguro Connect para WooCommerce Plugin pagbank-connect SQL Injection Authenticated (Shop Manager+) SQL Injection ≤ 4.44.3 CVE-2025-10142 Wordfence
6.5 Medium Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net Plugin peachpay-for-woocommerce SQL Injection Authenticated (Contributor+) SQL Injection via order_by Parameter ≤ 1.117.5 CVE-2025-9463 Wordfence
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-58985 Patchstack
4.9 Medium ELEX WooCommerce Google Shopping (Google Product Feed) Plugin elex-woocommerce-google-product-feed-plugin-basic SQL Injection Authenticated (Admin+) SQL Inejction ≤ 1.4.3 CVE-2025-10046 Wordfence
6.5 Medium Woocommerce Gifts Product Plugin woo-gift-product Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-58878 Patchstack
6.5 Medium Woocommerce Notify Updated Product Plugin woocommerce-notify-updated-product Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-58856 Patchstack
4.3 Medium WooCommerce Single Page Checkout Plugin woo-single-page-checkout Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-58804 Patchstack
4.3 Medium TrustMate.io – WooCommerce integration Plugin trustmate-io-integration-for-woocommerce Cross-Site Request Forgery WooCommerce integration plugin <= 1.16.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.16.0 CVE-2025-58802 Patchstack
4.3 Medium Custom WooCommerce Checkout Fields Editor Plugin add-fields-to-checkout-page-woocommerce Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-58799 Patchstack
5.3 Medium PeachPay Payments Plugin peachpay-for-woocommerce Broken Access Control No login needed ≤ 1.117.4 Fixed in 1.117.5 CVE-2025-58634 Patchstack
4.3 Medium Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Broken Access Control ≤ 4.1.0 Fixed in 4.2.0 CVE-2025-58599 Patchstack
6.6 Medium Klarna Order Management for WooCommerce Plugin klarna-order-management-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 1.9.8 Fixed in 1.9.9 CVE-2025-58598 Patchstack
5.9 Medium Risk Free Cash On Delivery (COD) – WooCommerce Plugin risk-free-cash-on-delivery-cod-woocommerce Cross-Site Scripting WooCommerce plugin <= 1.0.4 - Cross Site Scripting (XSS) ≤ 1.0.4 CVE-2025-48358 Patchstack
6.4 Medium Dynamic AJAX Product Filters for WooCommerce Plugin dynamic-ajax-product-filters-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter ≤ 1.3.7 CVE-2025-6255 Wordfence
6.4 Medium Dynamic AJAX Product Filters for WooCommerce Plugin dynamic-ajax-product-filters-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via name Parameter ≤ 1.3.7 CVE-2025-8073 Wordfence
5.3 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Broken Access Control No login needed ≤ 1.17.17 Fixed in 1.17.18 CVE-2025-58201 Patchstack
4.3 Medium Ni WooCommerce Customer Product Report Plugin ni-woocommerce-customer-product-report Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.2.4 CVE-2025-7827 Wordfence
6.4 Medium WPC Smart Quick View for WooCommerce Plugin woo-smart-quick-view Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woosq_btn Shortcode ≤ 4.2.1 CVE-2025-8618 Wordfence
6.4 Medium WPC Smart Compare for WooCommerce Plugin woo-smart-compare Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.4.7 CVE-2025-7496 Wordfence
6.6 Medium Woocommerce Blocks – Woolook Plugin woolook Local File Inclusion Woolook <= 1.7.0 - Authenticated (Admin+) Local File Inclusion ≤ 1.7.0 CVE-2024-8393 Wordfence
4.3 Medium YITH WooCommerce Popup Plugin yith-woocommerce-popup Cross-Site Request Forgery No login needed ≤ 1.48.0 Fixed in 1.48.1 CVE-2025-54675 Patchstack
5.4 Medium Product Configurator for WooCommerce Plugin product-configurator-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.4.4 Fixed in 1.5.0 CVE-2025-54674 Patchstack
6.5 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control Increase Your Sales <= 1.1.7 - Broken Access Control ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30993 Patchstack
6.5 Medium WooCommerce Fortnox Integration Plugin woocommerce-fortnox-integration Cross-Site Scripting ≤ 4.5.6 Fixed in 4.5.7 CVE-2025-47610 Patchstack
5.3 Medium FiboSearch Plugin ajax-search-for-woocommerce Broken Access Control No login needed ≤ 1.32.1 Fixed in 1.32.2 CVE-2025-47444 Patchstack
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.3.10 CVE-2025-7646 Wordfence
6.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via `author` Parameter ≤ 5.80.2 CVE-2025-5720 Wordfence
4.3 Medium Bonanza – WooCommerce Free Gifts Lite Plugin bonanza-woocommerce-free-gifts-lite Broken Access Control WooCommerce Free Gifts Lite <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Opt In Success ≤ 1.0.0 CVE-2025-6730 Wordfence
5.3 Medium WoodMart - Multipurpose WooCommerce Theme Broken Access Control Multipurpose WooCommerce Theme <= 8.2.6 - Improper Input Validation Leading to Unauthenticated Cart Manipulation No login needed ≤ 8.2.6 CVE-2025-8097 Wordfence
6.5 Medium B1.lt for WooCommerce Plugin b1-accounting SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 2.2.56 CVE-2025-6717 Wordfence
6.4 Medium Crowdfunding for WooCommerce Plugin crowdfunding-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter ≤ 3.1.14 CVE-2025-5767 Wordfence
4.3 Medium Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship Plugin biteship Broken Access Control Biteship <= 3.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) View Order Tracking Details ≤ 3.2.0 CVE-2025-5816 Wordfence
6.5 Medium Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Broken Access Control No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30959 Patchstack
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Broken Access Control No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-49319 Patchstack
4.3 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-54041 Patchstack
4.3 Medium WooCommerce Google Sheet Connector Plugin wc-gsheetconnector Cross-Site Request Forgery No login needed ≤ 1.3.20 Fixed in 1.4.0 CVE-2025-54030 Patchstack
6.4 Medium WPC Smart Compare for WooCommerce Plugin woo-smart-compare Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.4.6 CVE-2025-5530 Wordfence
4.3 Medium Order Delivery Date Pro for WooCommerce Plugin Information Disclosure Unauthenticated Arbitrary Post Title Disclosure No login needed 2.0 – < 12.6.0 Fixed in 12.6.0 CVE-2025-2942 WPScan
6.5 Medium WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 6.7.16 CVE-2025-3780 Wordfence
6.5 Medium Paytiko for WooCommerce Plugin paytiko Broken Access Control ≤ 1.3.21 CVE-2025-50032 Patchstack
4.3 Medium WooCommerce Shop Page Builder Plugin dzs-wootable Broken Access Control ≤ 2.27.7 CVE-2025-29001 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only