WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 701–750 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 6.2.2 CVE-2025-1287 Wordfence
5.9 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 5.4.1 CVE-2024-13640 Wordfence
6.1 Medium Wishlist for WooCommerce: Multi Wishlists Per Customer Plugin wish-list-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name No login needed ≤ 3.1.7 CVE-2024-13774 Wordfence
5.3 Medium Platform.ly for WooCommerce Plugin platformly-for-woocommerce Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 1.1.6 CVE-2024-13904 Wordfence
4.3 Medium WooMail - WooCommerce Email Customizer Plugin Broken Access Control WooCommerce Email Customizer <= 3.0.34 - Authenticated (Subscriber+) Missing Authorization to SQL Injection ≤ 3.0.34 CVE-2024-13747 Wordfence
4.3 Medium Zass - WooCommerce Theme for Handmade Artists and Artisans Theme Broken Access Control WooCommerce Theme for Handmade Artists and Artisans <= 3.9.9.10 - Missing Authorization to Authenticated (Subscriber+) Demo Import ≤ 3.9.9.10 CVE-2024-13810 Wordfence
4.3 Medium Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme Broken Access Control Multi Store Burger - Pizza & Food Delivery WooCommerce Theme <= 4.5.7 - Missing Authorization to Authenticated (Subscriber+) Demo Import ≤ 4.5.7 CVE-2024-13811 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Broken Access Control Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization ≤ 2.6.2 CVE-2024-13724 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed ≤ 2.6.2 CVE-2024-13682 Wordfence
6.1 Medium SKU Generator for WooCommerce Plugin sku-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.2 CVE-2024-9212 Wordfence
6.5 Medium Multilevel Referral Affiliate Plugin for WooCommerce Plugin multilevel-referral-plugin-for-woocommerce SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 2.28 CVE-2024-13750 Wordfence
6.1 Medium Currency Switcher for WooCommerce Plugin currency-switcher-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.16.2 CVE-2024-9217 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update ≤ 3.4.25 CVE-2025-1780 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 3.4.24 CVE-2024-13358 Wordfence
4.3 Medium NextMove Lite – Thank You Page for WooCommerce Plugin woo-thank-you-page-nextmove-lite Broken Access Control Thank You Page for WooCommerce <= 2.19.0 - Missing Authorization to Authenticated (Subscriber+) Deactivation Reason Submission ≤ 2.19.0 CVE-2024-10860 Wordfence
5.9 Medium Order Attachments for WooCommerce Plugin order-attachments-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 2.5.1 CVE-2024-13638 Wordfence
6.1 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.8.1 CVE-2025-1505 Wordfence
5.4 Medium WooCommerce Cart Count Shortcode Plugin Cross-Site Scripting Contributor+ XSS < 1.1.0 Fixed in 1.1.0 CVE-2024-10563 WPScan
4.3 Medium Order Limit for WooCommerce Plugin wc-order-limit-lite Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2025-26928 Patchstack
6.5 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting ≤ 2.8.0.1 Fixed in 2.8.1 CVE-2025-26878 Patchstack
6.5 Medium Direct Checkout Button for WooCommerce Plugin woo-direct-checkout-button Cross-Site Scripting ≤ 1.0 CVE-2025-27347 Patchstack
4.3 Medium WooCommerce Recargo de Equivalencia Plugin woo-recargo-de-equivalencia Cross-Site Request Forgery No login needed ≤ 1.6.24 CVE-2025-27342 Patchstack
6.5 Medium WooCommerce Display Products by Tags Plugin woocommerce-display-products-by-tags Cross-Site Scripting ≤ 1.0.0 CVE-2025-27331 Patchstack
6.4 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.0 CVE-2024-13461 Wordfence
5.3 Medium Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Plugin gift-voucher Broken Access Control Missing Authorization to Unauthenticated Price, Date, and Note Updates No login needed ≤ 4.4.9 CVE-2024-13520 Wordfence
6.4 Medium Login/Signup Popup ( Inline Form + Woocommerce ) Plugin easy-login-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via xoo_el_action Shortcode ≤ 2.8.5 CVE-2025-1064 Wordfence
4.3 Medium Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later Plugin flexible-wishlist Cross-Site Request Forgery Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification No login needed ≤ 1.2.26 CVE-2024-13718 Wordfence
6.1 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.6.6 CVE-2025-0864 Wordfence
5.3 Medium WooODT Lite – Delivery & pickup date time location for WooCommerce Plugin byconsole-woo-order-delivery-time Information Disclosure Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path Dsiclosure No login needed ≤ 2.5.1 CVE-2024-13540 Wordfence
5.3 Medium BigBuy Dropshipping Connector for WooCommerce Plugin bigbuy-wc-dropshipping-connector Information Disclosure Unauthenticated Full Path Disclosute No login needed ≤ 2.0.0 CVE-2024-13538 Wordfence
6.5 Medium Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure ≤ 2.9.4 CVE-2024-13525 Wordfence
5.4 Medium Return Refund and Exchange For WooCommerce Plugin woo-refund-and-exchange-lite Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 4.4.5 CVE-2024-13692 Wordfence
5.9 Medium Return Refund and Exchange For WooCommerce Plugin woo-refund-and-exchange-lite Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 4.4.5 CVE-2024-13641 Wordfence
6.4 Medium Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin gs-woo-brands Cross-Site Scripting Woocommerce Brands Plugin <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.2 CVE-2024-11746 Wordfence
6.5 Medium Product Blocks for WooCommerce Plugin product-blocks-for-woocommerce Cross-Site Scripting ≤ 1.9.1 Fixed in 2.0 CVE-2025-22674 Patchstack
4.3 Medium Hide Shipping Method For WooCommerce Plugin hide-shipping-method-for-woocommerce Broken Access Control ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-22694 Patchstack
6.5 Medium Korea for WooCommerce Plugin korea-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 1.1.11 Fixed in 1.1.12 CVE-2025-24639 Patchstack
5.4 Medium WooCommerce Support Ticket System Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Information Exposure ≤ 17.8 CVE-2024-13775 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.8 CVE-2024-11829 Wordfence
6.5 Medium MultiLoca - WooCommerce Multi Locations Inventory Management Plugin SQL Injection WooCommerce Multi Locations Inventory Management <= 4.1.11 - Authenticated (Subscriber+) SQL Injection ≤ 4.1.11 CVE-2024-13341 Wordfence
6.5 Medium Barcode Generator for WooCommerce Plugin embedding-barcodes-into-product-pages-and-orders Information Disclosure Sensitive Data Exposure ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-24597 Patchstack
5.8 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-22720 Patchstack
5.9 Medium Order Export for WooCommerce Plugin order-export-and-more-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 3.24 CVE-2024-13623 Wordfence
4.3 Medium Ni Sales Commission For WooCommerce Plugin ni-woo-sales-commission Broken Access Control Missing Authorization to Authenticated (Subscriber+) Commission Update ≤ 1.2.4 CVE-2024-13424 Wordfence
4.3 Medium Food Menu – Restaurant Menu & Online Ordering for WooCommerce Plugin tlp-food-menu Broken Access Control Restaurant Menu & Online Ordering for WooCommerce <= 5.1.4 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 5.1.4 CVE-2024-13415 Wordfence
6.5 Medium W2S – Migrate WooCommerce to Shopify Plugin w2s-migrate-woo-to-shopify Broken Access Control Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read ≤ 1.2.1 CVE-2024-12861 Wordfence
4.3 Medium ECPay Ecommerce for WooCommerce Plugin ecpay-ecommerce-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion ≤ 1.1.2411060 CVE-2024-13652 Wordfence
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
6.1 Medium WC Affiliate – A Complete WooCommerce Affiliate Plugin wc-affiliate Cross-Site Scripting A Complete WooCommerce Affiliate Plugin <= 2.4 - Reflected Cross-Site Scripting No login needed ≤ 2.4 CVE-2024-12334 Wordfence
4.3 Medium GoHero Store Customizer for WooCommerce Plugin personalize-woocommerce-cart-page Broken Access Control Missing Authorization to Unuthenticated Settings Update ≤ 3.5 CVE-2024-12826 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only