WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 551–600 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 12 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Commerce Coinbase For WooCommerce Plugin commerce-coinbase-for-woocommerce Broken Access Control No login needed ≤ 1.6.6 CVE-2026-25396 Patchstack
6.8 Medium Product File Upload for WooCommerce Plugin products-file-upload-for-woocommerce Arbitrary File Upload Arbitrary File Deletion No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-25328 Patchstack
7.5 High Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.9.0 Fixed in 6.0.0 CVE-2026-25317 Patchstack
9.3 Critical Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics SQL Injection No login needed ≤ 4.1.3 Fixed in 4.1.4 CVE-2026-24993 Patchstack
7.5 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Authentication Bypass Bypass Vulnerability No login needed ≤ 1.8.10 Fixed in 1.9.0 CVE-2026-24372 Patchstack
7.5 High Helpdesk Support Ticket System for WooCommerce Plugin support-ticket-system-for-woocommerce Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-23977 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.6.0 Fixed in 2.6.1 CVE-2026-23972 Patchstack
7.2 High Product Feed for WooCommerce Plugin webtoffee-product-feed PHP Object Injection ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-22480 Patchstack
6.5 Medium Product Filter for WooCommerce by WBW Plugin woo-product-filter Broken Access Control Missing Authorization to Unauthenticated Filter Data Deletion via TRUNCATE TABLE No login needed ≤ 3.1.2 CVE-2026-3138 Wordfence
9.8 Critical Woocommerce Custom Product Addons Pro Plugin Remote Code Execution Unauthenticated Remote Code Execution via Custom Pricing Formula No login needed ≤ 5.4.1 CVE-2026-4001 Wordfence
5.3 Medium ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More Plugin reviewx Information Disclosure WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.2.12 CVE-2025-10734 Wordfence
5.3 Medium ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More Plugin reviewx Information Disclosure WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure to Data Export No login needed ≤ 2.2.12 CVE-2025-10731 Wordfence
7.3 High ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More Plugin reviewx Remote Code Execution WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execution No login needed ≤ 2.2.12 CVE-2025-10679 Wordfence
6.5 Medium ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More Plugin reviewx Broken Access Control WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation No login needed ≤ 2.2.10 CVE-2025-10736 Wordfence
6.5 Medium ilGhera Carta Docente for WooCommerce Plugin wc-carta-docente Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter ≤ 1.5.0 CVE-2026-2421 Wordfence
7.5 High Fraud Prevention For Woocommerce Plugin woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-25443 Patchstack
9.0 Critical Woocommerce Wholesale Lead Capture Plugin woocommerce-wholesale-lead-capture Arbitrary File Upload No login needed ≤ 2.0.3.1 Fixed in 2.0.3.2 CVE-2026-27540 Patchstack
9.8 Critical Woocommerce Wholesale Lead Capture Plugin woocommerce-wholesale-lead-capture Privilege Escalation No login needed ≤ 2.0.3.1 Fixed in 2.0.3.2 CVE-2026-27542 Patchstack
5.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation No login needed ≤ 1.9.2 CVE-2026-1926 Wordfence
5.3 Medium Booster for WooCommerce Plugin woocommerce-jetpack Broken Access Control No login needed ≤ 7.11.3 Fixed in 7.11.3 CVE-2026-32586 Patchstack
7.5 High WowStore – Store Builder & Product Blocks for WooCommerce Plugin product-blocks SQL Injection Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter No login needed ≤ 4.4.3 CVE-2026-2579 Wordfence
5.3 Medium Advanced Product Fields (Product Addons) for WooCommerce Plugin advanced-product-fields-for-woocommerce Broken Access Control No login needed ≤ 1.6.18 Fixed in 1.6.19 CVE-2026-32457 Patchstack
6.5 Medium Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Cross-Site Scripting ≤ 1.0.7 Fixed in 1.0.8 CVE-2026-32450 Patchstack
6.5 Medium Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Cross-Site Request Forgery No login needed ≤ 13.5.2 Fixed in 13.5.2.1 CVE-2026-32443 Patchstack
5.4 Medium Gift Up Gift Cards for WordPress and WooCommerce Plugin gift-up Server-Side Request Forgery No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2026-32412 Patchstack
5.3 Medium WBW Currency Switcher for WooCommerce Plugin woo-currency Broken Access Control No login needed ≤ 2.2.5 Fixed in 2.2.6 CVE-2026-32410 Patchstack
4.3 Medium WPC Smart Wishlist for WooCommerce Plugin woo-smart-wishlist Broken Access Control ≤ 5.0.8 Fixed in 5.0.9 CVE-2026-32407 Patchstack
4.3 Medium WPC Product Bundles for WooCommerce Plugin woo-product-bundle Broken Access Control ≤ 8.4.5 Fixed in 8.4.6 CVE-2026-32406 Patchstack
6.5 Medium TeraWallet – For WooCommerce Plugin woo-wallet Other For WooCommerce plugin <= 1.5.15 - Race Condition ≤ 1.5.15 Fixed in 1.5.16 CVE-2026-32398 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-32372 Patchstack
4.3 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Broken Access Control ≤ 4.7.1 Fixed in 4.7.1.1 CVE-2026-31919 Patchstack
9.8 Critical Pix for WooCommerce Plugin payment-gateway-pix-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.5.0 CVE-2026-3891 Wordfence
7.2 High Checkout Field Editor (Checkout Manager) for WooCommerce Plugin woo-checkout-field-editor-pro Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field No login needed ≤ 2.1.7 CVE-2026-3231 Wordfence
7.5 High WooCommerce Plugin woocommerce Cross-Site Request Forgery Arbitrary Admin User Creation via CSRF No login needed 5.4.0 – < 5.4.4, 5.5.0 – < 5.4.5, 5.6.0 – < 5.6.3, … Fixed in 5.4.4 CVE-2026-3589 WPScan
9.1 Critical WooCommerce License Manager Plugin fs-license-manager Arbitrary File Upload ≤ 7.0.6 Fixed in 7.0.7 CVE-2026-28114 Patchstack
7.2 High Wholesale Suite Plugin woocommerce-wholesale-prices Privilege Escalation ≤ 2.2.6 Fixed in 2.2.7 CVE-2026-27541 Patchstack
7.1 High Claue - Clean, Minimal Elementor WooCommerce Theme claue Cross-Site Scripting Clean, Minimal Elementor WooCommerce Theme theme <= 2.2.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.7 CVE-2026-27376 Patchstack
7.5 High WooCommerce Order Details Plugin woocommerce-order-details Broken Access Control No login needed ≤ 3.1 CVE-2026-27374 Patchstack
6.5 Medium WooCommerce Coming Soon Product with Countdown Plugin woo-coming-soon-product Cross-Site Scripting ≤ 5.0 CVE-2026-27354 Patchstack
5.3 Medium Japanized for WooCommerce Plugin woocommerce-for-japan Broken Access Control Missing Authorization to Unauthenticated Paidy Order Manipulation No login needed ≤ 2.8.4 CVE-2026-1305 Wordfence
5.3 Medium WooCommerce Photo Reviews Plugin woocommerce-photo-reviews Content Injection No login needed ≤ 1.4.4 CVE-2026-28132 Patchstack
5.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay No login needed ≤ 6.4.7 CVE-2026-2385 Wordfence
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.8.0 Fixed in 5.9.0 CVE-2026-24946 Patchstack
8.8 High Woocommerce Category Banner Management Plugin banner-management-for-woocommerce PHP Object Injection ≤ 2.5.1 CVE-2026-22354 Patchstack
7.1 High Persian Woocommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.1 CVE-2026-22352 Patchstack
7.1 High RVCFDI para Woocommerce Plugin rvcfdi-para-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.1.8 CVE-2025-69386 Patchstack
6.5 Medium Cartify - WooCommerce Gutenberg Theme cartify Broken Access Control WooCommerce Gutenberg WordPress Theme theme <= 1.3 - Arbitrary Content Deletion ≤ 1.3 CVE-2025-69385 Patchstack
7.1 High WooCommerce Bulk Product Editor Plugin woocommerce-quick-product-editor Broken Access Control ≤ 3.0 CVE-2025-69381 Patchstack
7.2 High Product Filter for WooCommerce Plugin prdctfltr Privilege Escalation ≤ 9.1.2 CVE-2025-69378 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.9 Fixed in 2.6.0 CVE-2025-69328 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only