WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 651–672 of 672 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 14 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.4 High Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar ≤ 5.9.9 CVE-2024-1536 Wordfence
7.3 High Bulgarisation for WooCommerce Plugin Cross-Site Request Forgery No login needed ≤ 3.0.14 CVE-2024-2395 Wordfence
8.8 High Elite Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 7.1.7 CVE-2024-1986 Wordfence
8.8 High PDF Invoices and Packing Slips For WooCommerce Plugin pdf-invoices-and-packing-slips-for-woocommerce PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 1.3.7 CVE-2024-1773 Wordfence
8.8 High Avada | Website Builder For WordPress & WooCommerce Theme Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 7.11.4 CVE-2024-1468 Wordfence
8.8 High Conversios Plugin enhanced-e-commerce-for-woocommerce-store SQL Injection Authenticated (Subscriber+) SQL Injection via ee_syncProductCategory ≤ 7.0.7 CVE-2024-0786 Wordfence
7.3 High Oliver POS – A WooCommerce Point of Sale (POS) Plugin oliver-pos Broken Access Control A WooCommerce Point of Sale (POS) <= 2.4.2.1 - Missing Authorization No login needed ≤ 2.4.2.0 CVE-2024-0702 Wordfence
8.7 High ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks Plugin product-blocks PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2024-23512 Patchstack
8.2 High Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – Plugin mage-eventpress PHP Object Injection WordPress Event Manager for WooCommerce Plugin <= 4.1.1 is vulnerable to PHP Object Injection ≤ 4.1.1 Fixed in 4.1.2 CVE-2024-24796 Patchstack
7.1 High Portugal CTT Tracking for WooCommerce Plugin portugal-ctt-tracking-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 Fixed in 2.2 CVE-2024-24878 Patchstack
7.1 High WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc Plugin wp-sms Cross-Site Scripting WordPress WP SMS Plugin <= 6.5.2 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 6.5.2 Fixed in 6.5.3 CVE-2024-24881 Patchstack
7.6 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips SQL Injection WordPress WooCommerce PDF Invoices & Packing Slips Plugin <= 3.7.5 is vulnerable to SQL Injection ≤ 3.7.5 Fixed in 3.7.6 CVE-2024-22147 Patchstack
8.0 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Arbitrary File Upload WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload ≤ 2.4.3 Fixed in 2.4.4 CVE-2024-22135 Patchstack
8.0 High Product Import Export for WooCommerce Plugin product-import-export-for-woo Arbitrary File Upload WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload ≤ 2.3.7 Fixed in 2.3.8 CVE-2024-22152 Patchstack
8.2 High Montonio for WooCommerce Plugin montonio-for-woocommerce Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability affecting multiple WordPress plugins No login needed ≤ 6.0.1, ≤ 1.5.8, ≤ 4.6.6, … Fixed in 6.0.2 CVE-2022-40700 Patchstack
7.5 High All in One B2B for WooCommerce Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.3 CVE-2023-4703 WPScan
8.8 High WooCommerce Currency Switcher Plugin Local File Inclusion Authenticated (Low Privilege) Local File Inclusion < 1.3.7 Fixed in 1.3.7 CVE-2021-24566 WPScan
7.2 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Arbitrary File Upload Authenticated (Shop Manager+) Arbitrary File Upload ≤ 2.4.8 CVE-2023-6558 Wordfence
8.8 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 5.38.9 CVE-2023-6979 Wordfence
7.2 High Ni Purchase Order(PO) For WooCommerce Plugin ni-purchase-orderpo-for-woocommerce Arbitrary File Upload Admin+ File Upload to Remote Code Execution ≤ 1.2.1 CVE-2023-5957 WPScan
7.6 High WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Plugin erp SQL Injection WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injection ≤ 1.12.8 Fixed in 1.12.9 CVE-2024-21747 Patchstack
7.5 High WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Broken Access Control WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.6.1 is vulnerable to Insecure Direct Object References (IDOR) No login needed ≤ 7.6.1 Fixed in 7.6.2 CVE-2023-51502 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only