WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium MultiVendorX – WooCommerce Multivendor Marketplace Solutions Plugin dc-woocommerce-multi-vendor Broken Access Control WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post Deletion ≤ 4.2.22 CVE-2025-4101 Wordfence
6.5 Medium Product Carousel For WooCommerce – WoorouSell Plugin woorousell Cross-Site Scripting WoorouSell plugin <= 1.1.0 - Cross Site Scripting (XSS) ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-32180 Patchstack
5.3 Medium CURCY Plugin woocommerce-multi-currency Arbitrary Shortcode Execution No login needed ≤ 2.3.7 CVE-2025-47563 Patchstack
4.3 Medium Sharespine Woocommerce Connector Plugin sharespine-woocommerce-connector Broken Access Control ≤ 4.7.55 Fixed in 4.8.56 CVE-2025-48128 Patchstack
5.3 Medium WooCommerce POS Plugin woocommerce-pos Broken Access Control No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-48117 Patchstack
6.1 Medium WooCommerce Checkout & Funnel Builder by FunnelKit Plugin SQL Injection Admin+ SQL Injection No login needed < 3.10.2 Fixed in 3.10.2 CVE-2025-2203 WPScan
6.1 Medium Plugin Oficial – Getnet para WooCommerce Plugin Cross-Site Scripting Getnet para WooCommerce <= 1.7.3 - Unauthenticated Reflected XSS No login needed ≤ 1.7.3 CVE-2025-1303 WPScan
4.8 Medium Plugin Oficial – Getnet para WooCommerce Plugin Cross-Site Scripting Getnet para WooCommerce <= 1.7.3 - Admin+ Stored XSS ≤ 1.7.3 CVE-2025-1289 WPScan
4.8 Medium CTT Expresso para WooCommerce Plugin ctt-expresso-para-woocommerce Cross-Site Scripting Admin+ Stored XSS < 3.2.13 Fixed in 3.2.13 CVE-2024-6478 WPScan
6.4 Medium SMS Alert Order Notifications – WooCommerce Plugin sms-alert Cross-Site Scripting WooCommerce <= 3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_verify Shortcode ≤ 3.8.1 CVE-2025-3878 Wordfence
5.4 Medium 워드프레스 결제 심플페이 Plugin pgall-for-woocommerce Cross-Site Request Forgery No login needed ≤ 5.2.11 Fixed in 5.3.3 CVE-2025-47661 Patchstack
4.3 Medium Awin – Advertiser Tracking for WooCommerce Plugin awin-advertiser-tracking Cross-Site Request Forgery Advertiser Tracking for WooCommerce plugin <= 2.0.0 - CSRF to Product Feed Regeneration No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-47633 Patchstack
5.4 Medium Calculate Prices based on Distance For WooCommerce Plugin calculate-prices-based-on-distance-for-woocommerce Broken Access Control ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-47602 Patchstack
5.9 Medium Terms Popup On User Login Plugin terms-popup-on-user-login Cross-Site Scripting TPUL plugin <= 2.0.8 - Cross Site Scripting (XSS) ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-47592 Patchstack
5.4 Medium GS Variation Swatches for WooCommerce Plugin gs-woo-variation-swatches Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47526 Patchstack
6.5 Medium Product Time Countdown for WooCommerce Plugin product-countdown-for-woocommerce Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-47505 Patchstack
6.5 Medium Custom Checkout Fields for WooCommerce Plugin custom-checkout-fields-for-woocommerce Cross-Site Scripting ≤ 1.8.3 Fixed in 1.9.0 CVE-2025-47504 Patchstack
5.4 Medium PW WooCommerce Bulk Edit Plugin pw-bulk-edit Cross-Site Request Forgery No login needed ≤ 2.134 Fixed in 2.135 CVE-2025-47473 Patchstack
5.4 Medium Music Player for WooCommerce Plugin music-player-for-woocommerce Broken Access Control ≤ 1.5.1 Fixed in 1.6.0 CVE-2025-47472 Patchstack
4.7 Medium Integration for WooCommerce and Salesforce Plugin woo-salesforce-plugin-crm-perks Open Redirect No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2025-47455 Patchstack
4.3 Medium Product Quantity Dropdown For Woocommerce Plugin product-quantity-dropdown-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 Fixed in 1.3 CVE-2025-47451 Patchstack
4.3 Medium Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit Cross-Site Request Forgery Cross-Site Request Forgery to Limited User Meta Update No login needed ≤ 2.4.1 CVE-2025-2168 Wordfence
5.3 Medium Upsell Funnel Builder for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Other Unauthenticated Order Manipulation No login needed ≤ 3.0.0 CVE-2025-3743 Wordfence
6.5 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Server-Side Request Forgery WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter No login needed ≤ 3.1.2 CVE-2025-3775 Wordfence
5.3 Medium Bulk Assign Linked Products For WooCommerce Plugin wc-bulk-assign-linked-products Broken Access Control No login needed ≤ 2.1 CVE-2025-46489 Patchstack
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-39390 Patchstack
6.5 Medium ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.4.9 CVE-2025-3280 Wordfence
4.3 Medium Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Order Information Disclosure ≤ 4.1 CVE-2025-1284 Wordfence
5.3 Medium Advanced Linked Variations for Woocommerce Plugin linked-variation Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-46244 Patchstack
4.3 Medium Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2025-46243 Patchstack
6.4 Medium Tax Switch for WooCommerce Plugin tax-switch-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via class-name Parameter ≤ 1.4.2 CVE-2025-3814 Wordfence
6.1 Medium Coupon Affiliates – Affiliate Plugin for WooCommerce Plugin woo-coupon-usage Cross-Site Scripting Affiliate Plugin for WooCommerce <= 6.3.0 - Reflected Cross-Site Scripting via 'commission_summary' Parameter No login needed ≤ 6.3.0 CVE-2025-3598 Wordfence
6.5 Medium Bring Fraktguiden for WooCommerce Plugin bring-fraktguiden-for-woocommerce Broken Access Control ≤ 1.11.4 Fixed in 1.11.5 CVE-2025-39559 Patchstack
4.3 Medium Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.9.3 Fixed in 4.9.5 CVE-2025-39453 Patchstack
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-39457 Patchstack
5.3 Medium Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products Plugin password-protected Information Disclosure Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.7.7 CVE-2025-3453 Wordfence
4.3 Medium WooCommerce Social Login Plugin woo-social-login Cross-Site Request Forgery No login needed ≤ 2.8.3 Fixed in 2.8.3 CVE-2025-39472 Patchstack
6.5 Medium Checkout Files Upload for WooCommerce Plugin checkout-files-upload-woocommerce Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2025-39520 Patchstack
6.5 Medium Conditional Payments for WooCommerce Plugin conditional-payments-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-39563 Patchstack
6.5 Medium Conditional Shipping for WooCommerce Plugin conditional-shipping-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-39564 Patchstack
6.5 Medium Membership For WooCommerce Plugin membership-for-woocommerce Cross-Site Scripting ≤ 2.8.0 Fixed in 2.8.1 CVE-2025-39579 Patchstack
4.3 Medium Integration for WooCommerce and QuickBooks Plugin wp-woocommerce-quickbooks Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-39600 Patchstack
4.3 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Broken Access Control ≤ 3.9.5 Fixed in 3.9.6 CVE-2025-39602 Patchstack
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-26749 Patchstack
5.9 Medium Linet ERP-Woocommerce Integration Plugin linet-erp-woocommerce-integration Path Traversal Arbitrary File Read/Deletion ≤ 3.5.12 Fixed in 3.6.0 CVE-2025-31411 Patchstack
4.3 Medium Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic Plugin vagonic-sortable Broken Access Control ≤ 1.9 CVE-2025-32236 Patchstack
6.5 Medium Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Path Traversal Arbitrary File Download ≤ 7.1.5 Fixed in 7.1.6 CVE-2025-32209 Patchstack
6.5 Medium Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) Plugin swatchly Broken Access Control WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) 1.2.8 - 1.4.0 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update 1.2.8 – 1.4.0 CVE-2025-2719 Wordfence
5.3 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control No login needed ≤ 5.3.8 Fixed in 5.3.9 CVE-2025-26888 Patchstack
5.3 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary Options Update No login needed 1.0.4 – 1.2.1 CVE-2025-2568 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only