WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 551–600 of 675 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.1 High | Social Login - WordPress / WooCommerce | Authentication Bypass WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth provider No login needed |
≤ 2.7.7 |
CVE-2024-10114 |
Wordfence | |
| 8.5 High | Woocommerce Quote Calculator | SQL Injection |
≤ 1.1 |
CVE-2024-51626 |
Patchstack | |
| 7.3 High | WooCommerce PDF Vouchers | Broken Access Control Unauthenticated Multiple Vulnerabilities No login needed |
≤ 4.9.4 Fixed in 4.9.5 |
CVE-2024-39650 |
Patchstack | |
| 7.5 High | Woocommerce Product Design | Path Traversal Arbitrary File Download No login needed |
≤ 1.0.0 |
CVE-2024-50508 |
Patchstack | |
| 8.6 High | Woocommerce Product Design | Arbitrary File Deletion No login needed |
≤ 1.0.0 |
CVE-2024-50509 |
Patchstack | |
| 7.1 High | ACL Floating Cart for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.9 |
CVE-2024-49640 |
Patchstack | |
| 7.1 High | WooCommerce Maintenance Mode | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.1 |
CVE-2024-49651 |
Patchstack | |
| 8.8 High | WPC Smart Messages for WooCommerce | Local File Inclusion Authenticated (Subscriber+) Local File Inclusion |
≤ 4.2.1 |
CVE-2024-10436 |
Wordfence | |
| 7.1 High | YITH WooCommerce Product Add-Ons | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.14.1 Fixed in 4.14.2 |
CVE-2024-50448 |
Patchstack | |
| 8.8 High | WPC Shop as a Customer for WooCommerce | PHP Object Injection |
≤ 1.2.6 Fixed in 1.2.7 |
CVE-2024-50416 |
Patchstack | |
| 7.2 High | WooCommerce Order Proposal | Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation via Order Proposal |
≤ 2.0.5 |
CVE-2024-9927 |
Wordfence | |
| 7.6 High | FunnelKit Automations | SQL Injection |
≤ 3.1.2 Fixed in 3.2.0 |
CVE-2024-47328 |
Patchstack | |
| 7.1 High | EU/UK VAT Manager for WooCommerce | Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed |
≤ 2.12.14 Fixed in 3.0.0 |
CVE-2024-44061 |
Patchstack | |
| 8.5 High | CSV Product Import Export for WooCommerce | SQL Injection |
≤ 1.0.0 |
CVE-2024-49244 |
Patchstack | |
| 8.8 High | Bot for Telegram on WooCommerce | Information Disclosure Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass |
≤ 1.2.7 |
CVE-2024-9821 |
Wordfence | |
| 7.1 High | YITH WooCommerce Product Add-Ons | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.13.0 Fixed in 4.13.1 |
CVE-2024-47367 |
Patchstack | |
| 7.1 High | Robokassa payment gateway for Woocommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-47395 |
Patchstack | |
| 8.8 High | Product Enquiry for WooCommerce | PHP Object Injection Authenticated (Author+) PHP Object Injection in enquiry_detail.php |
≤ 2.2.33.33 |
CVE-2024-8922 |
Wordfence | |
| 8.8 High | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Privilege Escalation |
≤ 6.7.12 |
CVE-2024-8290 |
Wordfence | |
| 7.1 High | Product Slider for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.13.50 Fixed in 1.13.51 |
CVE-2024-45459 |
Patchstack | |
| 7.3 High | FOX – Currency Switcher Professional for WooCommerce | Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.4.2.1 |
CVE-2024-8271 |
Wordfence | |
| 8.5 High | Greenshift Woocommerce Addon | SQL Injection Subscriber+ SQL Injection |
< 1.9.8 Fixed in 1.9.8 |
CVE-2024-43943 |
Patchstack | |
| 8.8 High | WooCommerce Google Feed Manager | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Deletion |
≤ 2.8.0 |
CVE-2024-7258 |
Wordfence | |
| 8.5 High | Woo Products Widgets For Elementor | Local File Inclusion |
≤ 2.0.0 |
CVE-2024-43271 |
Patchstack | |
| 7.5 High | Stripe Payments For WooCommerce by Checkout | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 1.9.1 Fixed in 1.9.2 |
CVE-2024-43315 |
Patchstack | |
| 7.5 High | Docket (WooCommerce Collections / Wishlist / Watchlist) | Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed |
< 1.7.0 Fixed in 1.7.0 |
CVE-2024-43131 |
Patchstack | |
| 8.6 High | WooCommerce PDF Vouchers | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
< 4.9.5 Fixed in 4.9.5 |
CVE-2024-39651 |
Patchstack | |
| 7.5 High | HitPay Payment Gateway for WooCommerce | Information Disclosure Sensitive Data Exposure via Log File No login needed |
≤ 4.1.3 Fixed in 4.1.4 |
CVE-2024-38747 |
Patchstack | |
| 7.5 High | Wallet System for WooCommerce | Information Disclosure Sensitive Data Exposure via Exported File No login needed |
≤ 2.5.13 Fixed in 2.5.14 |
CVE-2024-38699 |
Patchstack | |
| 7.5 High | Woocommerce OpenPos | Information Disclosure Unauthenticated Sensitive Data Exposure No login needed |
≤ 6.4.4 |
CVE-2024-37935 |
Patchstack | |
| 7.1 High | Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | Cross-Site Scripting Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.6.14 - Cross Site Scripting (XSS) No login needed |
≤ 2.6.14 Fixed in 2.6.16 |
CVE-2024-43126 |
Patchstack | |
| 7.1 High | Products, Order & Customers Export for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.11 Fixed in 2.0.12 |
CVE-2024-43127 |
Patchstack | |
| 7.1 High | WC Marketplace | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.1.17 |
CVE-2024-43213 |
Patchstack | |
| 7.1 High | WooCommerce PDF Vouchers | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
< 4.9.5 Fixed in 4.9.5 |
CVE-2024-39652 |
Patchstack | |
| 7.2 High | CTX Feed | Privilege Escalation Arbitrary Options Update |
≤ 6.5.6 Fixed in 6.5.7 |
CVE-2024-38775 |
Patchstack | |
| 8.1 High | WooCommerce Customers Manager | Cross-Site Request Forgery Bulk Action via CSRF No login needed |
< 30.1 Fixed in 30.1 |
CVE-2024-3983 |
WPScan | |
| 7.3 High | WooCommerce - PDF Vouchers | Authentication Bypass PDF Vouchers <= 4.9.3 - Authentication Bypass to Voucher Vendor No login needed |
≤ 4.9.3 |
CVE-2024-7027 |
Wordfence | |
| 7.1 High | MakeCommerce for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.5.1 Fixed in 3.5.2 |
CVE-2024-37509 |
Patchstack | |
| 7.1 High | WooCommerce Predictive Search | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 6.0.1 |
CVE-2024-38669 |
Patchstack | |
| 7.1 High | Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.36.12 |
CVE-2024-38680 |
Patchstack | |
| 7.1 High | WooCommerce Report | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4.5 |
CVE-2024-38683 |
Patchstack | |
| 7.3 High | WooCommerce - Social Login | Authentication Bypass Social Login <= 2.7.3 - Unauthenticated Authentication Bypass No login needed |
≤ 2.7.3 |
CVE-2024-6635 |
Wordfence | |
| 7.3 High | WooCommerce - Social Login | Privilege Escalation Social Login <= 2.7.3 - Unauthenticated Privilege Escalation via One-Time Password No login needed |
≤ 2.7.3 |
CVE-2024-6637 |
Wordfence | |
| 8.6 High | Woocommerce OpenPos | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 6.4.4 |
CVE-2024-37932 |
Patchstack | |
| 8.8 High | Wallet for WooCommerce | SQL Injection Authenticated (Subscriber+) SQL Injection via 'search[value]' |
≤ 1.5.4 |
CVE-2024-6353 |
Wordfence | |
| 8.8 High | WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce | Local File Inclusion Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcode |
≤ 2.2.25 |
CVE-2024-5431 |
Wordfence | |
| 8.8 High | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Local File Inclusion Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusion |
≤ 5.5.6 |
CVE-2024-5455 |
Wordfence | |
| 8.1 High | WooCommerce Warranty Requests | Broken Access Control |
≤ 2.1.9 Fixed in 2.2.0 |
CVE-2023-37870 |
Patchstack | |
| 7.5 High | WooCommerce Stripe Payment Gateway | Broken Access Control Unauthenticated Broken Access Control No login needed |
≤ 7.4.0 Fixed in 7.4.1 |
CVE-2023-35049 |
Patchstack | |
| 7.1 High | FooEvents for WooCommerce | Arbitrary File Upload Improper Authorization to (Contributor+) Arbitrary File Upload |
≤ 1.19.20 |
CVE-2024-6000 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.