WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 701–750 of 1,255 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 6.2.2 |
CVE-2025-1287 |
Wordfence | |
| 5.9 Medium | Print Invoice & Delivery Notes for WooCommerce | Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed |
≤ 5.4.1 |
CVE-2024-13640 |
Wordfence | |
| 6.1 Medium | Wishlist for WooCommerce: Multi Wishlists Per Customer | Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name No login needed |
≤ 3.1.7 |
CVE-2024-13774 |
Wordfence | |
| 5.3 Medium | Platform.ly for WooCommerce | Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 1.1.6 |
CVE-2024-13904 |
Wordfence | |
| 4.3 Medium | WooMail - WooCommerce Email Customizer | Broken Access Control WooCommerce Email Customizer <= 3.0.34 - Authenticated (Subscriber+) Missing Authorization to SQL Injection |
≤ 3.0.34 |
CVE-2024-13747 |
Wordfence | |
| 4.3 Medium | Zass - WooCommerce Theme for Handmade Artists and Artisans | Broken Access Control WooCommerce Theme for Handmade Artists and Artisans <= 3.9.9.10 - Missing Authorization to Authenticated (Subscriber+) Demo Import |
≤ 3.9.9.10 |
CVE-2024-13810 |
Wordfence | |
| 4.3 Medium | Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce | Broken Access Control Multi Store Burger - Pizza & Food Delivery WooCommerce Theme <= 4.5.7 - Missing Authorization to Authenticated (Subscriber+) Demo Import |
≤ 4.5.7 |
CVE-2024-13811 |
Wordfence | |
| 4.3 Medium | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction | Broken Access Control Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization |
≤ 2.6.2 |
CVE-2024-13724 |
Wordfence | |
| 4.3 Medium | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction | Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed |
≤ 2.6.2 |
CVE-2024-13682 |
Wordfence | |
| 6.1 Medium | SKU Generator for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.2 |
CVE-2024-9212 |
Wordfence | |
| 6.5 Medium | Multilevel Referral Affiliate Plugin for WooCommerce | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 2.28 |
CVE-2024-13750 |
Wordfence | |
| 6.1 Medium | Currency Switcher for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.16.2 |
CVE-2024-9217 |
Wordfence | |
| 4.3 Medium | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update |
≤ 3.4.25 |
CVE-2025-1780 |
Wordfence | |
| 4.3 Medium | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update |
≤ 3.4.24 |
CVE-2024-13358 |
Wordfence | |
| 4.3 Medium | NextMove Lite – Thank You Page for WooCommerce | Broken Access Control Thank You Page for WooCommerce <= 2.19.0 - Missing Authorization to Authenticated (Subscriber+) Deactivation Reason Submission |
≤ 2.19.0 |
CVE-2024-10860 |
Wordfence | |
| 5.9 Medium | Order Attachments for WooCommerce | Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed |
≤ 2.5.1 |
CVE-2024-13638 |
Wordfence | |
| 6.1 Medium | Advanced AJAX Product Filters | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.8.1 |
CVE-2025-1505 |
Wordfence | |
| 5.4 Medium | WooCommerce Cart Count Shortcode | Cross-Site Scripting Contributor+ XSS |
< 1.1.0 Fixed in 1.1.0 |
CVE-2024-10563 |
WPScan | |
| 4.3 Medium | Order Limit for WooCommerce | Broken Access Control |
≤ 3.0.2 Fixed in 3.0.3 |
CVE-2025-26928 |
Patchstack | |
| 6.5 Medium | Autoship Cloud for WooCommerce Subscription Products | Cross-Site Scripting |
≤ 2.8.0.1 Fixed in 2.8.1 |
CVE-2025-26878 |
Patchstack | |
| 6.5 Medium | Direct Checkout Button for WooCommerce | Cross-Site Scripting |
≤ 1.0 |
CVE-2025-27347 |
Patchstack | |
| 4.3 Medium | WooCommerce Recargo de Equivalencia | Cross-Site Request Forgery No login needed |
≤ 1.6.24 |
CVE-2025-27342 |
Patchstack | |
| 6.5 Medium | WooCommerce Display Products by Tags | Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-27331 |
Patchstack | |
| 6.4 Medium | Autoship Cloud for WooCommerce Subscription Products | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.8.0 |
CVE-2024-13461 |
Wordfence | |
| 5.3 Medium | Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) | Broken Access Control Missing Authorization to Unauthenticated Price, Date, and Note Updates No login needed |
≤ 4.4.9 |
CVE-2024-13520 |
Wordfence | |
| 6.4 Medium | Login/Signup Popup ( Inline Form + Woocommerce ) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via xoo_el_action Shortcode |
≤ 2.8.5 |
CVE-2025-1064 |
Wordfence | |
| 4.3 Medium | Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later | Cross-Site Request Forgery Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification No login needed |
≤ 1.2.26 |
CVE-2024-13718 |
Wordfence | |
| 6.1 Medium | Active Products Tables for WooCommerce. Use constructor to create tables | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.6.6 |
CVE-2025-0864 |
Wordfence | |
| 5.3 Medium | WooODT Lite – Delivery & pickup date time location for WooCommerce | Information Disclosure Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path Dsiclosure No login needed |
≤ 2.5.1 |
CVE-2024-13540 |
Wordfence | |
| 5.3 Medium | BigBuy Dropshipping Connector for WooCommerce | Information Disclosure Unauthenticated Full Path Disclosute No login needed |
≤ 2.0.0 |
CVE-2024-13538 |
Wordfence | |
| 6.5 Medium | Customer Email Verification for WooCommerce | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure |
≤ 2.9.4 |
CVE-2024-13525 |
Wordfence | |
| 5.4 Medium | Return Refund and Exchange For WooCommerce | Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference |
≤ 4.4.5 |
CVE-2024-13692 |
Wordfence | |
| 5.9 Medium | Return Refund and Exchange For WooCommerce | Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed |
≤ 4.4.5 |
CVE-2024-13641 |
Wordfence | |
| 6.4 Medium | Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands | Cross-Site Scripting Woocommerce Brands Plugin <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.2 |
CVE-2024-11746 |
Wordfence | |
| 6.5 Medium | Product Blocks for WooCommerce | Cross-Site Scripting |
≤ 1.9.1 Fixed in 2.0 |
CVE-2025-22674 |
Patchstack | |
| 4.3 Medium | Hide Shipping Method For WooCommerce | Broken Access Control |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2025-22694 |
Patchstack | |
| 6.5 Medium | Korea for WooCommerce | Information Disclosure Sensitive Data Exposure |
≤ 1.1.11 Fixed in 1.1.12 |
CVE-2025-24639 |
Patchstack | |
| 5.4 Medium | WooCommerce Support Ticket System | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Information Exposure |
≤ 17.8 |
CVE-2024-13775 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.1.8 |
CVE-2024-11829 |
Wordfence | |
| 6.5 Medium | MultiLoca - WooCommerce Multi Locations Inventory Management | SQL Injection WooCommerce Multi Locations Inventory Management <= 4.1.11 - Authenticated (Subscriber+) SQL Injection |
≤ 4.1.11 |
CVE-2024-13341 |
Wordfence | |
| 6.5 Medium | Barcode Generator for WooCommerce | Information Disclosure Sensitive Data Exposure |
≤ 2.0.2 Fixed in 2.0.3 |
CVE-2025-24597 |
Patchstack | |
| 5.8 Medium | Booking and Rental Manager | Broken Access Control No login needed |
≤ 2.2.1 Fixed in 2.2.2 |
CVE-2025-22720 |
Patchstack | |
| 5.9 Medium | Order Export for WooCommerce | Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed |
≤ 3.24 |
CVE-2024-13623 |
Wordfence | |
| 4.3 Medium | Ni Sales Commission For WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Commission Update |
≤ 1.2.4 |
CVE-2024-13424 |
Wordfence | |
| 4.3 Medium | Food Menu – Restaurant Menu & Online Ordering for WooCommerce | Broken Access Control Restaurant Menu & Online Ordering for WooCommerce <= 5.1.4 - Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 5.1.4 |
CVE-2024-13415 |
Wordfence | |
| 6.5 Medium | W2S – Migrate WooCommerce to Shopify | Broken Access Control Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read |
≤ 1.2.1 |
CVE-2024-12861 |
Wordfence | |
| 4.3 Medium | ECPay Ecommerce for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion |
≤ 1.1.2411060 |
CVE-2024-13652 |
Wordfence | |
| 4.3 Medium | Print Barcode Labels for your WooCommerce products/orders | Broken Access Control |
≤ 3.4.10 Fixed in 3.4.11 |
CVE-2025-24603 |
Patchstack | |
| 6.1 Medium | WC Affiliate – A Complete WooCommerce Affiliate | Cross-Site Scripting A Complete WooCommerce Affiliate Plugin <= 2.4 - Reflected Cross-Site Scripting No login needed |
≤ 2.4 |
CVE-2024-12334 |
Wordfence | |
| 4.3 Medium | GoHero Store Customizer for WooCommerce | Broken Access Control Missing Authorization to Unuthenticated Settings Update |
≤ 3.5 |
CVE-2024-12826 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.