WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 701–750 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.3 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 2.7.3 Fixed in 2.7.4 CVE-2025-68029 Patchstack
5.4 Medium WordPress & WooCommerce Scraper Plugin, Import Data from Any Site Plugin wp_scraper Server-Side Request Forgery No login needed ≤ 1.0.7 CVE-2025-62088 Patchstack
4.3 Medium Order Cancellation & Returns for WooCommerce Plugin wc-order-cancellation-return Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.1.11 CVE-2025-49352 Patchstack
4.3 Medium Orders Chat for WooCommerce Plugin orders-chat-for-woocommerce Broken Access Control ≤ 1.2.0 CVE-2025-49356 Patchstack
4.3 Medium Live Shopping & Shoppable Videos For WooCommerce Plugin live-shopping-video-streams Cross-Site Request Forgery No login needed ≤ 2.2.0 CVE-2025-62080 Patchstack
5.3 Medium Live Shopping & Shoppable Videos For WooCommerce Plugin live-shopping-video-streams Broken Access Control No login needed ≤ 2.2.0 CVE-2025-62081 Patchstack
5.4 Medium Serial Codes Generator and Validator with WooCommerce Support Plugin serial-codes-generator-and-validator Broken Access Control ≤ 2.8.2 Fixed in 2.8.3 CVE-2025-62091 Patchstack
5.9 Medium WooCommerce Parcelas Plugin woocommerce-parcelas Cross-Site Scripting ≤ 1.3.5 CVE-2025-62750 Patchstack
6.5 Medium Maximum Products per User for WooCommerce Plugin maximum-products-per-user-for-woocommerce Cross-Site Scripting ≤ 4.4.3 Fixed in 4.4.4 CVE-2025-62096 Patchstack
6.5 Medium Web and WooCommerce Addons for WPBakery Builder Plugin vc-addons-by-bit14 Cross-Site Scripting ≤ 1.5 CVE-2025-62748 Patchstack
7.5 High Knowband Mobile App Builder for wooCommerce Plugin Broken Access Control Unauthenticated Arbitrary User Deletion No login needed < 3.0.0 Fixed in 3.0.0 CVE-2025-13029 WPScan
7.2 High Lucky Wheel for WooCommerce – Spin a Sale Plugin woo-lucky-wheel Remote Code Execution Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags ≤ 1.1.13 CVE-2025-14509 Wordfence
5.3 Medium ShopMagic Plugin shopmagic-for-woocommerce Broken Access Control No login needed ≤ 4.7.2 Fixed in 4.7.3 CVE-2025-69093 Patchstack
6.5 Medium Combo Offers WooCommerce Plugin woo-combo-offers Cross-Site Scripting ≤ 4.2 Fixed in 4.3 CVE-2025-69088 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 3.2.0 - Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.3.0 CVE-2025-69027 Patchstack
6.5 Medium BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control ≤ 4.6.7 Fixed in 4.7.1 CVE-2025-69024 Patchstack
5.3 Medium Product Loops for WooCommerce Plugin product-loops Broken Access Control No login needed ≤ 2.1.2 CVE-2025-68994 Patchstack
5.3 Medium Share, Print and PDF Products for WooCommerce Plugin share-print-pdf-woocommerce Broken Access Control No login needed ≤ 3.1.2 CVE-2025-68993 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-67909 Patchstack
6.5 Medium Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Plugin amount-left-free-shipping-woocommerce Cross-Site Scripting ≤ 2.4.9 Fixed in 2.5.0 CVE-2025-68528 Patchstack
8.5 High Brands for WooCommerce Plugin brands-for-woocommerce SQL Injection ≤ 3.8.6.3 Fixed in 3.8.6.4 CVE-2025-68519 Patchstack
9.8 Critical Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Remote Code Execution Unauthenticated Remote Code Execution No login needed ≤ 5.8.0 CVE-2025-13773 Wordfence
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 2.7.0 - Broken Access Control No login needed ≤ 2.7.0 Fixed in 2.7.1 CVE-2023-52210 Patchstack
6.1 Medium Product Table for WooCommerce Plugin woo-product-table Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.0.8 CVE-2025-12398 Wordfence
5.4 Medium FiboSearch – Ajax Search for WooCommerce Plugin ajax-search-for-woocommerce Cross-Site Scripting Ajax Search for WooCommerce <= 1.32.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via thegem_te_search Shortcode ≤ 1.32.0 CVE-2025-14298 Wordfence
9.8 Critical File Uploader for WooCommerce Plugin file-uploader-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload via add-image-data No login needed ≤ 1.0.3 CVE-2025-13329 Wordfence
4.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.3 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_subscr' ≤ 1.3.7.3 CVE-2025-13110 Wordfence
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-64266 Patchstack
7.5 High WooCommerce Recover Abandoned Cart Plugin rac Broken Access Control Arbitrary Content Deletion No login needed ≤ 24.6.0 Fixed in 24.7.0 CVE-2025-64222 Patchstack
8.8 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60083 Patchstack
8.1 High Riode Plugin riode Local File Inclusion No login needed ≤ 1.6.23 CVE-2025-60071 Patchstack
9.3 Critical Advance Seat Reservation Management for WooCommerce Plugin scw-seat-reservation SQL Injection No login needed ≤ 3.1 CVE-2025-58951 Patchstack
7.2 High Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Privilege Escalation ≤ 1.2 Fixed in 1.3 CVE-2025-49379 Patchstack
6.5 Medium Fancy Product Designer | WooCommerce Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Race Condition No login needed ≤ 6.4.8 CVE-2025-13231 Wordfence
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control No login needed ≤ 2.10.0 Fixed in 2.11.0 CVE-2025-67929 Patchstack
5.3 Medium Sendinblue for WooCommerce Plugin woocommerce-sendinblue-newsletter-subscription Broken Access Control No login needed ≤ 4.0.49 Fixed in 4.0.50 CVE-2025-66128 Patchstack
5.3 Medium OnPay.io for WooCommerce Plugin onpay-io-for-woocommerce Broken Access Control No login needed ≤ 1.0.47 Fixed in 1.0.48 CVE-2025-64638 Patchstack
2.7 Low WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce plugin <= 6.7.24 - Broken Access Control ≤ 6.7.24 Fixed in 6.7.25 CVE-2025-54004 Patchstack
5.9 Medium Fancy Product Designer | WooCommerce Plugin Information Disclosure Unauthenticated Information Disclosure and PHAR Deserialization via 'url' Parameter No login needed ≤ 6.4.8 CVE-2025-13439 Wordfence
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Content Injection Unauthenticated HTML Injection No login needed ≤ 2.10.0 CVE-2025-9207 Wordfence
5.3 Medium Eyewear prescription form Plugin eyewear-prescription-form Broken Access Control Missing Authorization to Unauthenticated Arbitrary WooCommerce Category Deletion No login needed ≤ 6.0.1 CVE-2025-14365 Wordfence
6.4 Medium YITH WooCommerce Quick View Plugin yith-woocommerce-quick-view Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode ≤ 2.7.0 CVE-2025-8617 Wordfence
7.5 High افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce Plugin payamito-sms-woocommerce SQL Injection Unauthenticated Time-Based Blind SQL Injection No login needed ≤ 1.3.5 CVE-2025-13077 Wordfence
5.3 Medium Eyewear prescription form Plugin eyewear-prescription-form Broken Access Control Missing Authorization to Unauthenticated Arbitrary WooCommerce Product Creation No login needed ≤ 6.0.1 CVE-2025-14366 Wordfence
7.5 High FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder SQL Injection Funnel Builder for WooCommerce Checkout <= 3.13.1.5 - Unauthenticated SQL Injection No login needed ≤ 3.13.1.5 CVE-2025-14169 Wordfence
5.3 Medium Hippoo Mobile App for WooCommerce Plugin hippoo Broken Access Control Missing Authorization to Unauthenticated Limited File Write No login needed ≤ 1.7.1 CVE-2025-12655 Wordfence
5.3 Medium Product Filtering by Categories, Tags, Price Range for WooCommerce Plugin filter-plus Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 1.1.6 CVE-2025-13314 Wordfence
5.3 Medium Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Wishlist Deletion No login needed ≤ 1.1.10 CVE-2025-13440 Wordfence
4.3 Medium Kirim.Email WooCommerce Integration Plugin kirimemail-woocommerce-integration Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2.9 CVE-2025-14165 Wordfence
4.3 Medium Premmerce Brands for WooCommerce Plugin premmerce-woocommerce-brands Broken Access Control Missing Authorization To Authenticated (Subscriber+) Brand Permalink Settings Update ≤ 1.2.13 CVE-2025-12783 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only