WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 651–700 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 14 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Hyyan WooCommerce Polylang Integration Plugin woo-poly-integration Broken Access Control ≤ 1.5.0 CVE-2026-24585 Patchstack
5.3 Medium SumUp Payment Gateway For WooCommerce Plugin sumup-payment-gateway-for-woocommerce Broken Access Control No login needed ≤ 2.7.9 Fixed in 2.7.10 CVE-2026-24583 Patchstack
5.4 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control ≤ 2.9.5 Fixed in 2.9.6 CVE-2026-24581 Patchstack
5.3 Medium Ryviu – Product Reviews for WooCommerce Plugin ryviu Broken Access Control Product Reviews for WooCommerce plugin <= 3.1.26 - Broken Access Control No login needed ≤ 3.1.26 CVE-2026-24562 Patchstack
4.3 Medium Fraud Prevention For Woocommerce Plugin woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers Information Disclosure Sensitive Data Exposure ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-24553 Patchstack
6.5 Medium Email Inquiry & Cart Options for WooCommerce Plugin woocommerce-email-inquiry-cart-options Cross-Site Scripting ≤ 3.5.0 CVE-2026-24526 Patchstack
5.3 Medium YITH WooCommerce Request A Quote Plugin yith-woocommerce-request-a-quote Broken Access Control No login needed ≤ 2.46.0 Fixed in 2.46.1 CVE-2026-24366 Patchstack
5.4 Medium Stock Manager for WooCommerce Plugin woocommerce-stock-manager Cross-Site Request Forgery No login needed ≤ 3.6.0 Fixed in 3.6.0 CVE-2026-24365 Patchstack
5.3 Medium CTX Feed Plugin webappick-product-feed-for-woocommerce Broken Access Control No login needed ≤ 6.6.18 Fixed in 6.6.19 CVE-2026-22461 Patchstack
9.8 Critical Registration & Login with Mobile Phone Number for WooCommerce Plugin registration-login-with-mobile-phone-number Broken Access Control No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-69052 Patchstack
8.5 High FooEvents for WooCommerce Plugin fooevents SQL Injection ≤ 1.20.4 Fixed in 1.20.5 CVE-2025-69045 Patchstack
8.1 High Bajaar - Highly Customizable WooCommerce Theme bajaar Local File Inclusion Highly Customizable WooCommerce WordPress Theme theme <= 2.1.0 - Local File Inclusion No login needed ≤ 2.1.0 CVE-2025-69004 Patchstack
7.1 High Omnichannel for WooCommerce Plugin codistoconnect Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-68041 Patchstack
9.4 Critical Order Listener for WooCommerce Plugin woc-order-alert Broken Access Control No login needed ≤ 3.6.1 Fixed in 3.6.2 CVE-2025-68018 Patchstack
6.5 Medium onepay Payment Gateway For WooCommerce Plugin onepay-payment-gateway-for-woocommerce Broken Access Control Other Vulnerability Type No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-68016 Patchstack
6.5 Medium Payment Gateway Authorize.Net CIM for WooCommerce Plugin authnet-cim-for-woo Broken Access Control Arbitrary Content Deletion ≤ 2.1.2 CVE-2025-68013 Patchstack
7.1 High GLS Shipping for WooCommerce Plugin gls-shipping-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-68011 Patchstack
6.5 Medium TaxCloud for WooCommerce Plugin simple-sales-tax Broken Access Control No login needed ≤ 8.3.8 Fixed in 8.4.0 CVE-2025-67958 Patchstack
9.3 Critical MailerLite – WooCommerce integration Plugin woo-mailerlite SQL Injection WooCommerce integration plugin <= 3.1.2 - SQL Injection No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-67945 Patchstack
8.1 High Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Plugin dokan-lite Broken Access Control Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure ≤ 4.2.4 CVE-2025-14977 Wordfence
5.3 Medium PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) Plugin peachpay-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 1.119.8 CVE-2025-14978 Wordfence
5.3 Medium PAYGENT for WooCommerce Plugin woocommerce-for-paygent-payment-main Broken Access Control Missing Authorization to Unauthenticated Payment Callback Manipulation No login needed ≤ 2.4.6 CVE-2025-14078 Wordfence
9.8 Critical Registration & Login with Mobile Phone Number for WooCommerce Plugin Authentication Bypass No login needed ≤ 1.3.1 CVE-2025-10484 Wordfence
6.5 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation ≤ 2.7.2 CVE-2025-14450 Wordfence
5.3 Medium Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Plugin woo-rede Broken Access Control Missing Authorization to Unauthenticated Rede Order Logs Deletion No login needed ≤ 5.1.5 CVE-2026-0942 Wordfence
5.3 Medium Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Plugin woo-rede Other Unauthenticated Order Status Manipulation No login needed ≤ 5.1.2 CVE-2026-0939 Wordfence
6.5 Medium MailerLite - WooCommerce integration Plugin woo-mailerlite Broken Access Control WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion ≤ 3.1.3 CVE-2026-1000 Wordfence
5.3 Medium Fancy Product Designer | WooCommerce Plugin Information Disclosure Unauthenticated Full Path Disclosure via 'pdf' Parameter No login needed ≤ 6.4.8 CVE-2025-15526 Wordfence
5.3 Medium PayHere Payment Gateway Plugin for WooCommerce Plugin payhere-payment-gateway Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 2.3.9 CVE-2025-15475 Wordfence
5.3 Medium Perfit WooCommerce Plugin perfit-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed ≤ 1.0.1 CVE-2025-14173 Wordfence
5.3 Medium Netcash WooCommerce Payment Gateway Plugin netcash-pay-now-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 4.1.3 CVE-2025-14880 Wordfence
4.9 Medium Shipping Rates by City for WooCommerce Plugin flat-shipping-rate-by-city-for-woocommerce SQL Injection Authenticated (Shop Manager+) SQL Injection via 'cities' Parameter ≤ 1.0.3 CVE-2026-0678 Wordfence
9.8 Critical Integration Opvius AI for WooCommerce Plugin woosa-ai-for-woocommerce Arbitrary File Deletion Unauthenticated Arbitrary File Deletion/Read via Path Traversal No login needed ≤ 1.3.0 CVE-2025-14301 Wordfence
5.3 Medium miniOrange OTP Verification and SMS Notification for WooCommerce Plugin miniorange-sms-order-notification-otp-verification Broken Access Control Missing Authorization to Unauthenticated Notification Settings Modification No login needed ≤ 4.3.8 CVE-2025-14948 Wordfence
7.5 High WooCommerce Square Plugin woocommerce-square Broken Access Control Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in get_token_by_id No login needed 4.2.0 – < 4.2.3, 4.3.0 – < 4.3.2, 4.4.0 – < 4.4.2, … Fixed in 4.2.3 CVE-2025-13457 Wordfence
6.4 Medium BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce Plugin bulk-image-alt-text-with-yoast Cross-Site Scripting Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2025-15019 Wordfence
5.3 Medium Japanized for WooCommerce Plugin woocommerce-for-japan Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 2.7.17 CVE-2025-14886 Wordfence
7.2 High Brevo for WooCommerce Plugin woocommerce-sendinblue-newsletter-subscription Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.0.49 CVE-2025-14436 Wordfence
8.5 High WooCommerce Orders & Customers Exporter Plugin woocommerce-orders-ei SQL Injection ≤ 5.4 CVE-2025-22713 Patchstack
5.3 Medium Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Change No login needed ≤ 3.1.4 CVE-2025-14460 Wordfence
4.4 Medium Email Customizer for WooCommerce | Drag and Drop Email Templates Builder Plugin email-customizer-for-woocommerce Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Email Template Content ≤ 2.6.7 CVE-2025-13974 Wordfence
7.5 High Reviewify Plugin review-for-discount Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary WooCommerce Coupon Creation No login needed ≤ 1.0.7 CVE-2025-14070 Wordfence
6.4 Medium QR Code for WooCommerce order emails, PDF invoices, packing slips Plugin qr-code-tag-for-wc-from-goaskle-com Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via Shortcode Attributes ≤ 1.9.42 CVE-2025-14626 Wordfence
6.1 Medium Premmerce WooCommerce Customers Manager Plugin woo-customers-manager Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.14 CVE-2025-13369 Wordfence
8.2 High iPaymu Payment Gateway for WooCommerce Plugin ipaymu-for-woocommerce Price Manipulation Missing Authentication to Unauthenticated Payment Bypass and Order Information Disclosure No login needed ≤ 2.0.2 CVE-2026-0656 Wordfence
6.1 Medium HBLPAY Payment Gateway for WooCommerce Plugin hblpay-payment-gateway-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'cusdata' Parameter No login needed ≤ 5.0.0 CVE-2025-14875 Wordfence
6.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via displayName Parameter ≤ 5.93.1 CVE-2025-14891 Wordfence
7.1 High Woocommerce Sales Funnel Builder Plugin woosales Cross-Site Scripting Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins No login needed ≤ 1.1, ≤ 1.2 CVE-2025-30631 Patchstack
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Cross-Site Scripting ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-69334 Patchstack
5.3 Medium ilGhera Support System for WooCommerce Plugin wc-support-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket Deletion No login needed ≤ 1.2.6 CVE-2025-14034 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only