WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 651–700 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 14 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorization to Unauthenticated Table Rates Deletion No login needed ≤ 4.2.19 CVE-2025-2789 Wordfence
4.3 Medium Woocommerce Role Pricing Plugin woocommerce-role-pricing Cross-Site Request Forgery No login needed ≤ 3.5.6 CVE-2025-32271 Patchstack
4.3 Medium Sequential Order Numbers for WooCommerce Plugin sequential-order-numbers-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.6.2 Fixed in 3.6.3 CVE-2025-32263 Patchstack
6.5 Medium Official CleverReach Plugin for WooCommerce Plugin cleverreach-wc Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 3.4.6 Fixed in 3.4.7 CVE-2025-32241 Patchstack
4.3 Medium AdMail – Multilingual Back in-Stock Notifier for WooCommerce Plugin admail Broken Access Control ≤ 1.7.0 CVE-2025-32234 Patchstack
6.5 Medium Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods Cross-Site Scripting ≤ 3.2.8 Fixed in 3.2.9 CVE-2025-32207 Patchstack
6.5 Medium Search, Filters & Merchandising for WooCommerce Plugin instantsearch-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.0.58 Fixed in 3.0.59 CVE-2025-32181 Patchstack
6.5 Medium Pallet Packaging for WooCommerce Plugin pallet-packaging-for-woocommerce Broken Access Control No login needed ≤ 1.1.15 Fixed in 1.1.16 CVE-2025-22285 Patchstack
6.5 Medium Shopify to WooCommerce Migration Plugin migrate-shopify-to-woocommerce Broken Access Control Settings Change No login needed ≤ 1.3.0 CVE-2025-31795 Patchstack
5.4 Medium WR Price List Manager For Woocommerce Plugin wr-price-list-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.0.8 CVE-2025-31794 Patchstack
6.5 Medium Free Woocommerce Product Table View Plugin free-product-table-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.78 CVE-2025-31758 Patchstack
5.4 Medium Barcode Generator for WooCommerce Plugin embedding-barcodes-into-product-pages-and-orders Broken Access Control Settings Change ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-31879 Patchstack
4.3 Medium ShipDepot for WooCommerce Plugin ship-depot Broken Access Control ≤ 1.2.19 CVE-2025-31866 Patchstack
4.3 Medium Simple Sticky Add To Cart For WooCommerce Plugin sticky-add-to-cart-woo Broken Access Control ≤ 1.4.9 CVE-2025-31854 Patchstack
4.3 Medium OpenAI Tools for WordPress & WooCommerce Plugin openai-tools-for-wp-wc Broken Access Control ≤ 2.2.1 CVE-2025-31843 Patchstack
4.3 Medium Printus Plugin printus-cloud-printing-for-woocommerce Broken Access Control ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-31830 Patchstack
5.4 Medium Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods Broken Access Control ≤ 3.2.8 Fixed in 3.2.9 CVE-2025-31826 Patchstack
4.3 Medium Product Notices for WooCommerce Plugin product-notices-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-31807 Patchstack
5.4 Medium Shiptimize for WooCommerce Plugin shiptimize-for-woocommerce Broken Access Control Settings Change ≤ 3.1.86 CVE-2025-31802 Patchstack
4.3 Medium Gift Cards for WooCommerce Plugin woo-giftcards Broken Access Control ≤ 1.5.8 CVE-2025-31781 Patchstack
5.4 Medium Free Woocommerce Product Table View Plugin free-product-table-for-woocommerce Broken Access Control ≤ 1.78 CVE-2025-31757 Patchstack
6.5 Medium Quantity Dynamic Pricing & Bulk Discounts for WooCommerce Plugin wholesale-pricing-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-31598 Patchstack
4.3 Medium ELEX WooCommerce Request a Quote Plugin elex-request-a-quote Broken Access Control ≤ 2.3.9 CVE-2025-31406 Patchstack
6.5 Medium Shipmondo – A complete shipping solution for WooCommerce Plugin pakkelabels-for-woocommerce Information Disclosure A complete shipping solution for WooCommerce plugin <= 5.0.3 - Authenticated Arbitrary WordPress Option Disclosure ≤ 5.0.3 Fixed in 5.0.4 CVE-2025-27001 Patchstack
5.9 Medium WooCommerce Plugin woocommerce Cross-Site Scripting ≤ 9.7.0 Fixed in 9.7.1 CVE-2025-26762 Patchstack
6.5 Medium Product Table For WooCommerce Plugin product-table-for-woocommerce Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-22638 Patchstack
6.5 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Cross-Site Scripting Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) ≤ 1.4.7 CVE-2025-22644 Patchstack
4.3 Medium Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets Plugin wpsyncsheets-woocommerce Broken Access Control ≤ 1.8.2 Fixed in 1.9 CVE-2025-22667 Patchstack
4.3 Medium EAN for WooCommerce Plugin ean-for-woocommerce Broken Access Control ≤ 5.3.5 Fixed in 5.4.0 CVE-2025-22673 Patchstack
4.3 Medium Gift Message for WooCommerce Plugin gift-message-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-30923 Patchstack
4.3 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control ≤ 7.2.3 Fixed in 7.2.4 CVE-2025-30909 Patchstack
6.5 Medium افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) Plugin persian-woocommerce-shipping Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2025-30898 Patchstack
4.3 Medium Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-30888 Patchstack
4.3 Medium Product Author for WooCommerce Plugin wc-product-author Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-30872 Patchstack
4.3 Medium Serial Codes Generator and Validator with WooCommerce Support Plugin serial-codes-generator-and-validator Cross-Site Request Forgery No login needed ≤ 2.7.7 Fixed in 2.7.8 CVE-2025-30854 Patchstack
5.3 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-30839 Patchstack
4.3 Medium TWB Woocommerce Reviews Plugin twb-woocommerce-reviews Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-30801 Patchstack
4.7 Medium Scheduled & Automatic Order Status Controller for WooCommerce Plugin order-status-rules-for-woocommerce Open Redirect No login needed ≤ 3.7.1 Fixed in 3.7.2 CVE-2025-30781 Patchstack
5.9 Medium Accounting for WooCommerce Plugin accounting-for-woocommerce Cross-Site Scripting ≤ 1.6.8 Fixed in 1.6.9 CVE-2025-26929 Patchstack
4.9 Medium Product Import Export for WooCommerce Plugin product-import-export-for-woo Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function ≤ 2.5.0 CVE-2025-1769 Wordfence
4.1 Medium Product Labels For Woocommerce Plugin SQL Injection Admin+ SQLi < 1.5.9 Fixed in 1.5.9 CVE-2024-12109 WPScan
4.1 Medium Product Labels For Woocommerce Plugin SQL Injection Admin+ SQLi < 1.5.11 Fixed in 1.5.11 CVE-2024-10638 WPScan
4.9 Medium Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function ≤ 2.6.2 CVE-2025-1973 Wordfence
6.5 Medium WooCommerce Multivendor Marketplace – REST API Plugin wcfm-marketplace-rest-api SQL Injection REST API <= 1.6.2 - Authenticated (Subscriber+) SQL Injection ≤ 1.6.2 CVE-2025-1311 Wordfence
4.9 Medium Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function ≤ 2.6.0 CVE-2024-13920 Wordfence
6.5 Medium Recapture for WooCommerce Plugin recapture-for-woocommerce Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.0.43 Fixed in 1.0.44 CVE-2025-26899 Patchstack
6.5 Medium WC Affiliate – A Complete WooCommerce Affiliate Plugin wc-affiliate Broken Access Control A Complete WooCommerce Affiliate Plugin <= 2.5.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via wf-export-all ≤ 2.5.3 CVE-2024-12336 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 CVE-2025-1527 Wordfence
6.4 Medium Finale Lite – Sales Countdown Timer & Discount for WooCommerce Plugin finale-woocommerce-sales-countdown-timer-discount Cross-Site Scripting Sales Countdown Timer & Discount for WooCommerce <= 2.19.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Countdown Timer ≤ 2.19.0 CVE-2024-12589 Wordfence
4.3 Medium Skrill Official Plugin official-skrill-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.66 Fixed in 1.0.67 CVE-2025-28876 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only