WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 651–700 of 2,122 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Hyyan WooCommerce Polylang Integration | Broken Access Control |
≤ 1.5.0 |
CVE-2026-24585 |
Patchstack | |
| 5.3 Medium | SumUp Payment Gateway For WooCommerce | Broken Access Control No login needed |
≤ 2.7.9 Fixed in 2.7.10 |
CVE-2026-24583 |
Patchstack | |
| 5.4 Medium | Points and Rewards for WooCommerce | Broken Access Control |
≤ 2.9.5 Fixed in 2.9.6 |
CVE-2026-24581 |
Patchstack | |
| 5.3 Medium | Ryviu – Product Reviews for WooCommerce | Broken Access Control Product Reviews for WooCommerce plugin <= 3.1.26 - Broken Access Control No login needed |
≤ 3.1.26 |
CVE-2026-24562 |
Patchstack | |
| 4.3 Medium | Fraud Prevention For Woocommerce | Information Disclosure Sensitive Data Exposure |
≤ 2.3.2 Fixed in 2.3.3 |
CVE-2026-24553 |
Patchstack | |
| 6.5 Medium | Email Inquiry & Cart Options for WooCommerce | Cross-Site Scripting |
≤ 3.5.0 |
CVE-2026-24526 |
Patchstack | |
| 5.3 Medium | YITH WooCommerce Request A Quote | Broken Access Control No login needed |
≤ 2.46.0 Fixed in 2.46.1 |
CVE-2026-24366 |
Patchstack | |
| 5.4 Medium | Stock Manager for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 3.6.0 Fixed in 3.6.0 |
CVE-2026-24365 |
Patchstack | |
| 5.3 Medium | CTX Feed | Broken Access Control No login needed |
≤ 6.6.18 Fixed in 6.6.19 |
CVE-2026-22461 |
Patchstack | |
| 9.8 Critical | Registration & Login with Mobile Phone Number for WooCommerce | Broken Access Control No login needed |
≤ 1.3.1 Fixed in 1.3.2 |
CVE-2025-69052 |
Patchstack | |
| 8.5 High | FooEvents for WooCommerce | SQL Injection |
≤ 1.20.4 Fixed in 1.20.5 |
CVE-2025-69045 |
Patchstack | |
| 8.1 High | Bajaar - Highly Customizable WooCommerce | Local File Inclusion Highly Customizable WooCommerce WordPress Theme theme <= 2.1.0 - Local File Inclusion No login needed |
≤ 2.1.0 |
CVE-2025-69004 |
Patchstack | |
| 7.1 High | Omnichannel for WooCommerce | Cross-Site Scripting No login needed |
≤ 1.3.65 |
CVE-2025-68041 |
Patchstack | |
| 9.4 Critical | Order Listener for WooCommerce | Broken Access Control No login needed |
≤ 3.6.1 Fixed in 3.6.2 |
CVE-2025-68018 |
Patchstack | |
| 6.5 Medium | onepay Payment Gateway For WooCommerce | Broken Access Control Other Vulnerability Type No login needed |
≤ 1.1.2 Fixed in 1.1.3 |
CVE-2025-68016 |
Patchstack | |
| 6.5 Medium | Payment Gateway Authorize.Net CIM for WooCommerce | Broken Access Control Arbitrary Content Deletion |
≤ 2.1.2 |
CVE-2025-68013 |
Patchstack | |
| 7.1 High | GLS Shipping for WooCommerce | Cross-Site Scripting No login needed |
≤ 1.4.0 Fixed in 1.4.1 |
CVE-2025-68011 |
Patchstack | |
| 6.5 Medium | TaxCloud for WooCommerce | Broken Access Control No login needed |
≤ 8.3.8 Fixed in 8.4.0 |
CVE-2025-67958 |
Patchstack | |
| 9.3 Critical | MailerLite – WooCommerce integration | SQL Injection WooCommerce integration plugin <= 3.1.2 - SQL Injection No login needed |
≤ 3.1.2 Fixed in 3.1.3 |
CVE-2025-67945 |
Patchstack | |
| 8.1 High | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy | Broken Access Control Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure |
≤ 4.2.4 |
CVE-2025-14977 |
Wordfence | |
| 5.3 Medium | PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) | Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed |
≤ 1.119.8 |
CVE-2025-14978 |
Wordfence | |
| 5.3 Medium | PAYGENT for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Payment Callback Manipulation No login needed |
≤ 2.4.6 |
CVE-2025-14078 |
Wordfence | |
| 9.8 Critical | Registration & Login with Mobile Phone Number for WooCommerce | Authentication Bypass No login needed |
≤ 1.3.1 |
CVE-2025-10484 |
Wordfence | |
| 6.5 Medium | Wallet System for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation |
≤ 2.7.2 |
CVE-2025-14450 |
Wordfence | |
| 5.3 Medium | Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit | Broken Access Control Missing Authorization to Unauthenticated Rede Order Logs Deletion No login needed |
≤ 5.1.5 |
CVE-2026-0942 |
Wordfence | |
| 5.3 Medium | Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit | Other Unauthenticated Order Status Manipulation No login needed |
≤ 5.1.2 |
CVE-2026-0939 |
Wordfence | |
| 6.5 Medium | MailerLite - WooCommerce integration | Broken Access Control WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion |
≤ 3.1.3 |
CVE-2026-1000 |
Wordfence | |
| 5.3 Medium | Fancy Product Designer | WooCommerce | Information Disclosure Unauthenticated Full Path Disclosure via 'pdf' Parameter No login needed |
≤ 6.4.8 |
CVE-2025-15526 |
Wordfence | |
| 5.3 Medium | PayHere Payment Gateway Plugin for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed |
≤ 2.3.9 |
CVE-2025-15475 |
Wordfence | |
| 5.3 Medium | Perfit WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed |
≤ 1.0.1 |
CVE-2025-14173 |
Wordfence | |
| 5.3 Medium | Netcash WooCommerce Payment Gateway | Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed |
≤ 4.1.3 |
CVE-2025-14880 |
Wordfence | |
| 4.9 Medium | Shipping Rates by City for WooCommerce | SQL Injection Authenticated (Shop Manager+) SQL Injection via 'cities' Parameter |
≤ 1.0.3 |
CVE-2026-0678 |
Wordfence | |
| 9.8 Critical | Integration Opvius AI for WooCommerce | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion/Read via Path Traversal No login needed |
≤ 1.3.0 |
CVE-2025-14301 |
Wordfence | |
| 5.3 Medium | miniOrange OTP Verification and SMS Notification for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Notification Settings Modification No login needed |
≤ 4.3.8 |
CVE-2025-14948 |
Wordfence | |
| 7.5 High | WooCommerce Square | Broken Access Control Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in get_token_by_id No login needed |
4.2.0 – < 4.2.3, 4.3.0 – < 4.3.2, 4.4.0 – < 4.4.2, … Fixed in 4.2.3 |
CVE-2025-13457 |
Wordfence | |
| 6.4 Medium | BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce | Cross-Site Scripting Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.1 |
CVE-2025-15019 |
Wordfence | |
| 5.3 Medium | Japanized for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed |
≤ 2.7.17 |
CVE-2025-14886 |
Wordfence | |
| 7.2 High | Brevo for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 4.0.49 |
CVE-2025-14436 |
Wordfence | |
| 8.5 High | WooCommerce Orders & Customers Exporter | SQL Injection |
≤ 5.4 |
CVE-2025-22713 |
Patchstack | |
| 5.3 Medium | Piraeus Bank WooCommerce Payment Gateway | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Change No login needed |
≤ 3.1.4 |
CVE-2025-14460 |
Wordfence | |
| 4.4 Medium | Email Customizer for WooCommerce | Drag and Drop Email Templates Builder | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Email Template Content |
≤ 2.6.7 |
CVE-2025-13974 |
Wordfence | |
| 7.5 High | Reviewify | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary WooCommerce Coupon Creation No login needed |
≤ 1.0.7 |
CVE-2025-14070 |
Wordfence | |
| 6.4 Medium | QR Code for WooCommerce order emails, PDF invoices, packing slips | Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via Shortcode Attributes |
≤ 1.9.42 |
CVE-2025-14626 |
Wordfence | |
| 6.1 Medium | Premmerce WooCommerce Customers Manager | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.1.14 |
CVE-2025-13369 |
Wordfence | |
| 8.2 High | iPaymu Payment Gateway for WooCommerce | Price Manipulation Missing Authentication to Unauthenticated Payment Bypass and Order Information Disclosure No login needed |
≤ 2.0.2 |
CVE-2026-0656 |
Wordfence | |
| 6.1 Medium | HBLPAY Payment Gateway for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting via 'cusdata' Parameter No login needed |
≤ 5.0.0 |
CVE-2025-14875 |
Wordfence | |
| 6.4 Medium | Customer Reviews for WooCommerce | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via displayName Parameter |
≤ 5.93.1 |
CVE-2025-14891 |
Wordfence | |
| 7.1 High | Woocommerce Sales Funnel Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins No login needed |
≤ 1.1, ≤ 1.2 |
CVE-2025-30631 |
Patchstack | |
| 6.5 Medium | Wishlist for WooCommerce | Cross-Site Scripting |
≤ 3.3.0 Fixed in 3.3.1 |
CVE-2025-69334 |
Patchstack | |
| 5.3 Medium | ilGhera Support System for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket Deletion No login needed |
≤ 1.2.6 |
CVE-2025-14034 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.