WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Primer MyData for Woocommerce Plugin primer-mydata Path Traversal No login needed ≤ 4.2.8 Fixed in 4.2.9 CVE-2025-69325 Patchstack
7.5 High Sync Master Sheet – Product Sync with Google Sheet for WooCommerce Plugin product-sync-master-sheet Broken Access Control Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-68834 Patchstack
7.5 High WooCommerce Coming Soon Product with Countdown Plugin woo-coming-soon-product Local File Inclusion ≤ 5.0 Fixed in 5.1 CVE-2025-68552 Patchstack
7.1 High Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.1.1 Fixed in 8.1.2 CVE-2025-68501 Patchstack
6.5 Medium Addonify Floating Cart For WooCommerce Plugin addonify-floating-cart Broken Access Control No login needed ≤ 1.2.17 CVE-2025-68025 Patchstack
6.5 Medium Addonify – WooCommerce Wishlist Plugin addonify-wishlist Broken Access Control WooCommerce Wishlist plugin <= 2.0.15 - Settings Change No login needed ≤ 2.0.15 Fixed in 2.0.16 CVE-2025-68024 Patchstack
6.5 Medium Addonify – Compare Products For WooCommerce Plugin addonify-compare-products Broken Access Control Compare Products For WooCommerce plugin <= 1.1.17 - Settings Change No login needed ≤ 1.1.17 Fixed in 1.1.18 CVE-2025-68023 Patchstack
7.3 High Plugin BlueX for WooCommerce Plugin bluex-for-woocommerce Broken Access Control No login needed ≤ 3.1.6 CVE-2025-68022 Patchstack
6.5 Medium UPI QR Code Payment Gateway for WooCommerce Plugin upi-qr-code-payment-for-woocommerce Broken Access Control No login needed ≤ 1.5.1 Fixed in 1.6.1 CVE-2025-67969 Patchstack
4.3 Medium YayMail Plugin yaymail Broken Access Control WooCommerce Email Customizer plugin <= 4.3.2 - Broken Access Control ≤ 4.3.2 Fixed in 4.3.3 CVE-2026-27327 Patchstack
7.5 High Product Table and List Builder for WooCommerce Lite Plugin wc-product-table-lite SQL Injection Unauthenticated Time-Based SQL Injection via 'search' Parameter No login needed ≤ 4.6.2 CVE-2026-2232 Wordfence
7.5 High Sales Countdown Timer for WooCommerce and Plugin sctv-sales-countdown-timer Local File Inclusion ≤ 1.1.9 Fixed in 1.1.9 CVE-2026-27052 Patchstack
4.3 Medium WiserReview Product Reviews for WooCommerce Plugin wiser-review Broken Access Control ≤ 2.9 Fixed in 3.0 CVE-2026-25318 Patchstack
5.3 Medium Alma Plugin alma-gateway-for-woocommerce Broken Access Control No login needed ≤ 5.16.1 Fixed in 5.16.2 CVE-2026-24999 Patchstack
5.3 Medium Ultimate Gift Cards For WooCommerce Plugin woo-gift-cards-lite Broken Access Control No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-24375 Patchstack
7.2 High YITH WooCommerce Compare Plugin yith-woocommerce-compare PHP Object Injection Deserialization of untrusted data ≤ 3.6.0 Fixed in 3.7.0 CVE-2026-22333 Patchstack
4.3 Medium Whatsiplus Scheduled Notification for Woocommerce Plugin whatsiplus-scheduled-notification-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to 'wsnfw_save_users_settings' AJAX Action No login needed ≤ 1.0.1 CVE-2026-1455 Wordfence
5.3 Medium Mega Store Woocommerce Theme mega-store-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Page Creation and Settings Change No login needed ≤ 5.9 CVE-2025-14357 Wordfence
7.2 High CTX Feed – WooCommerce Product Feed Manager Plugin webappick-product-feed-for-woocommerce Broken Access Control WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation ≤ 6.6.11 CVE-2025-12975 Wordfence
5.3 Medium Checkout Field Manager (Checkout Manager) for WooCommerce Plugin woocommerce-checkout-manager Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed ≤ 7.8.5 CVE-2025-13930 Wordfence
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Missing Authentication to Unauthenticated Order Modification No login needed ≤ 4.7.8 CVE-2025-14294 Wordfence
5.3 Medium Checkout Field Manager (Checkout Manager) for WooCommerce Plugin woocommerce-checkout-manager Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 7.8.1 CVE-2025-12500 Wordfence
6.4 Medium Printful Integration for WooCommerce Plugin printful-shipping-for-woocommerce Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 2.2.11 CVE-2025-12375 Wordfence
8.8 High Advanced AJAX Product Filters Plugin woocommerce-ajax-filters PHP Object Injection Authenticated (Author+) PHP Object Injection via Live Composer Compatibility ≤ 3.1.9.6 CVE-2026-1426 Wordfence
4.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' ≤ 6.4.7 CVE-2026-2386 Wordfence
7.2 High Product Addons for Woocommerce – Product Options with Custom Fields Plugin woo-custom-product-addons Remote Code Execution Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter ≤ 3.1.0 CVE-2026-2296 Wordfence
7.2 High Cart All In One For WooCommerce Plugin woo-cart-all-in-one Remote Code Execution Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting ≤ 1.1.21 CVE-2026-2019 Wordfence
4.3 Medium PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Broken Access Control Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification ≤ 5.6.0 CVE-2026-1906 Wordfence
4.3 Medium EmailKit – Email Customizer for WooCommerce & WP Plugin emailkit Broken Access Control Email Customizer for WooCommerce & WP <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification ≤ 1.6.2 CVE-2026-1925 Wordfence
4.3 Medium Order Splitter for WooCommerce Plugin wc-order-splitter Broken Access Control Missing Authorization to Authenticated (Subscriber+) Order Information Exposure ≤ 5.3.5 CVE-2025-12075 Wordfence
7.7 High Zarinpal Gateway for WooCommerce Plugin zarinpal-woocommerce-payment-gateway Broken Access Control Improper Access Control to Payment Status Update No login needed ≤ 5.0.16 CVE-2026-2592 Wordfence
7.5 High Flexi Product Slider and Grid for WooCommerce Plugin flexi-product-slider-grid Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute ≤ 1.0.5 CVE-2026-1988 Wordfence
7.5 High BlueSnap Payment Gateway for WooCommerce Plugin bluesnap-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Manipulation No login needed ≤ 3.4.0 CVE-2026-0692 Wordfence
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via media[].href Parameter No login needed ≤ 5.97.0 CVE-2026-1316 Wordfence
5.8 Medium Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) Plugin Broken Access Control Uni CPO (Premium) <= 4.9.60 - Missing Authorization to Unauthenticated Arbitrary Attachment and Dropbox File Deletion No login needed ≤ 4.9.60 CVE-2025-13391 Wordfence
4.3 Medium Invoct – PDF Invoices & Billing for WooCommerce Plugin kirilkirkov-pdf-invoice-manager Broken Access Control PDF Invoices & Billing for WooCommerce <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Information Exposure ≤ 1.6 CVE-2026-1748 Wordfence
6.5 Medium OpenPix Plugin openpix-for-woocommerce Broken Access Control Subscriber+ Payment Gateway Settings Reset ≤ 2.13.3 CVE-2025-15400 WPScan
4.3 Medium WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Plugin wc-multivendor-membership Broken Access Control WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecure Direct Object Reference to Update Membership Payment ≤ 2.11.8 CVE-2025-15147 Wordfence
7.2 High WCFM - WooCommerce Frontend Manager Plugin wc-frontend-manager Broken Access Control WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Update ≤ 6.7.24 CVE-2026-0845 Wordfence
4.9 Medium SIBS - WooCommerce Plugin sibs-woocommerce SQL Injection WooCommerce <= 2.2.0 - Authenticated (Admin+) SQL Injection via 'referencedId' Parameter ≤ 2.2.0 CVE-2026-1370 Wordfence
5.3 Medium Fortis for WooCommerce Plugin fortis-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Update to Paid via 'wc-api' Endpoint No login needed ≤ 1.2.0 CVE-2026-0679 Wordfence
6.5 Medium MyRewards – Loyalty Points and Rewards for WooCommerce Plugin woorewards Broken Access Control Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Loyalty Rule Modification ≤ 5.6.1 CVE-2025-15260 Wordfence
5.3 Medium Chapa Payment Gateway Plugin for WooCommerce Plugin chapa-payment-gateway-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.3 CVE-2025-15482 Wordfence
5.3 Medium Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics Information Disclosure Sensitive Data Exposure No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2026-24992 Patchstack
7.5 High VidShop – Shoppable Videos for WooCommerce Plugin vidshop-for-woocommerce SQL Injection Shoppable Videos for WooCommerce <= 1.1.4 - Unauthenticated Time-Based SQL Injection via 'fields' No login needed ≤ 1.1.4 CVE-2026-0702 Wordfence
4.4 Medium Order Minimum/Maximum Amount Limits for WooCommerce Plugin order-minimum-amount-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via Hide Add to Cart Content Fields ≤ 4.6.8 CVE-2026-1381 Wordfence
5.3 Medium Link Invoice Payment for WooCommerce Plugin invoice-payment-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Partial Payment Creation/Cancellation No login needed ≤ 2.8.0 CVE-2025-14971 Wordfence
5.3 Medium Wizit Gateway for WooCommerce Plugin wizit-gateway-for-woocommerce Broken Access Control Missing Authentication to Unauthenticated Arbitrary Order Cancellation No login needed ≤ 1.3.1 CVE-2025-14843 Wordfence
5.3 Medium File Uploads Addon for WooCommerce Plugin woo-addon-uploads Arbitrary File Upload Broken Access Control No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2026-24625 Patchstack
5.3 Medium Bayarcash WooCommerce Plugin bayarcash-wc Broken Access Control No login needed ≤ 4.3.13 Fixed in 4.3.14 CVE-2026-24606 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only