WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.
Showing 651–672 of 672 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.4 High | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar |
≤ 5.9.9 |
CVE-2024-1536 |
Wordfence | |
| 7.3 High | Bulgarisation for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 3.0.14 |
CVE-2024-2395 |
Wordfence | |
| 8.8 High | Elite Booster for WooCommerce | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 7.1.7 |
CVE-2024-1986 |
Wordfence | |
| 8.8 High | PDF Invoices and Packing Slips For WooCommerce | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection |
≤ 1.3.7 |
CVE-2024-1773 |
Wordfence | |
| 8.8 High | Avada | Website Builder For WordPress & WooCommerce | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload |
≤ 7.11.4 |
CVE-2024-1468 |
Wordfence | |
| 8.8 High | Conversios | SQL Injection Authenticated (Subscriber+) SQL Injection via ee_syncProductCategory |
≤ 7.0.7 |
CVE-2024-0786 |
Wordfence | |
| 7.3 High | Oliver POS – A WooCommerce Point of Sale (POS) | Broken Access Control A WooCommerce Point of Sale (POS) <= 2.4.2.1 - Missing Authorization No login needed |
≤ 2.4.2.0 |
CVE-2024-0702 |
Wordfence | |
| 8.7 High | ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks | PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed |
≤ 3.1.4 Fixed in 3.1.5 |
CVE-2024-23512 |
Patchstack | |
| 8.2 High | Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – | PHP Object Injection WordPress Event Manager for WooCommerce Plugin <= 4.1.1 is vulnerable to PHP Object Injection |
≤ 4.1.1 Fixed in 4.1.2 |
CVE-2024-24796 |
Patchstack | |
| 7.1 High | Portugal CTT Tracking for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1 Fixed in 2.2 |
CVE-2024-24878 |
Patchstack | |
| 7.1 High | WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc | Cross-Site Scripting WordPress WP SMS Plugin <= 6.5.2 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 6.5.2 Fixed in 6.5.3 |
CVE-2024-24881 |
Patchstack | |
| 7.6 High | PDF Invoices & Packing Slips for WooCommerce | SQL Injection WordPress WooCommerce PDF Invoices & Packing Slips Plugin <= 3.7.5 is vulnerable to SQL Injection |
≤ 3.7.5 Fixed in 3.7.6 |
CVE-2024-22147 |
Patchstack | |
| 8.0 High | Order Export & Order Import for WooCommerce | Arbitrary File Upload WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload |
≤ 2.4.3 Fixed in 2.4.4 |
CVE-2024-22135 |
Patchstack | |
| 8.0 High | Product Import Export for WooCommerce | Arbitrary File Upload WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload |
≤ 2.3.7 Fixed in 2.3.8 |
CVE-2024-22152 |
Patchstack | |
| 8.2 High | Montonio for WooCommerce | Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability affecting multiple WordPress plugins No login needed |
≤ 6.0.1, ≤ 1.5.8, ≤ 4.6.6, … Fixed in 6.0.2 |
CVE-2022-40700 |
Patchstack | |
| 7.5 High | All in One B2B for WooCommerce | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.0.3 |
CVE-2023-4703 |
WPScan | |
| 8.8 High | WooCommerce Currency Switcher | Local File Inclusion Authenticated (Low Privilege) Local File Inclusion |
< 1.3.7 Fixed in 1.3.7 |
CVE-2021-24566 |
WPScan | |
| 7.2 High | Export and Import Users and Customers | Arbitrary File Upload Authenticated (Shop Manager+) Arbitrary File Upload |
≤ 2.4.8 |
CVE-2023-6558 |
Wordfence | |
| 8.8 High | Customer Reviews for WooCommerce | Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload |
≤ 5.38.9 |
CVE-2023-6979 |
Wordfence | |
| 7.2 High | Ni Purchase Order(PO) For WooCommerce | Arbitrary File Upload Admin+ File Upload to Remote Code Execution |
≤ 1.2.1 |
CVE-2023-5957 |
WPScan | |
| 7.6 High | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting | SQL Injection WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injection |
≤ 1.12.8 Fixed in 1.12.9 |
CVE-2024-21747 |
Patchstack | |
| 7.5 High | WooCommerce Stripe Payment Gateway | Broken Access Control WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.6.1 is vulnerable to Insecure Direct Object References (IDOR) No login needed |
≤ 7.6.1 Fixed in 7.6.2 |
CVE-2023-51502 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.