WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 751–800 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 16 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce Cross-Site Scripting ≤ 4.6.0 Fixed in 4.7.0 CVE-2025-24755 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Cross-Site Scripting ≤ 4.2.13 Fixed in 4.2.14 CVE-2025-24706 Patchstack
5.3 Medium WooCommerce Quick View Plugin woo-quick-view Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.1 Fixed in 1.1.3 CVE-2025-24705 Patchstack
5.9 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Cross-Site Scripting ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-24681 Patchstack
5.9 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Cross-Site Scripting ≤ 33.0.8 Fixed in 33.0.9 CVE-2025-24668 Patchstack
5.9 Medium Wishlist for WooCommerce Plugin wt-woocommerce-wishlist Cross-Site Scripting ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-24657 Patchstack
5.9 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.7.1 Fixed in 4.7.2 CVE-2025-24644 Patchstack
5.4 Medium WooCommerce Cloak Affiliate Links Plugin woocommerce-cloak-affiliate-links Cross-Site Request Forgery No login needed ≤ 1.0.35 Fixed in 1.0.36 CVE-2025-24647 Patchstack
4.3 Medium Taxonomy/Term and Role based Discounts for WooCommerce Plugin taxonomy-discounts-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 5.1 Fixed in 5.2 CVE-2025-24625 Patchstack
5.3 Medium Build Private Store For Woocommerce Plugin build-private-store-for-woocommerce Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-24633 Patchstack
5.3 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Broken Access Control No login needed ≤ 3.8.7 Fixed in 3.9.0 CVE-2025-24596 Patchstack
6.5 Medium Linet ERP-Woocommerce Integration Plugin linet-erp-woocommerce-integration Cross-Site Request Forgery CSRF to Broken Access Control No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-24594 Patchstack
4.3 Medium Product Size Charts Plugin for WooCommerce Plugin woo-advanced-product-size-chart Broken Access Control ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-23991 Patchstack
4.3 Medium Variation Swatches for WooCommerce Plugin th-variation-swatches Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Reset No login needed 1.0.8 – 1.3.2 CVE-2024-13511 Wordfence
4.4 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting ≤ 1.9.80 CVE-2024-13519 Wordfence
4.3 Medium ShipWorks Connector for Woocommerce Plugin shipworks-e-commerce-bridge Cross-Site Request Forgery Cross-Site Request Forgery to Service Password/Username Update No login needed ≤ 5.2.5 CVE-2024-13317 Wordfence
5.4 Medium Admin and Customer Messages After Order for WooCommerce Plugin Arbitrary File Upload Authenticated (Subscriber+) Limited File Upload to Cross-Site Scripting ≤ 13.2 CVE-2024-13355 Wordfence
6.5 Medium Product Carousel For WooCommerce – WoorouSell Plugin woorousell Cross-Site Scripting WoorouSell plugin <= 1.1.0 - Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2025-22724 Patchstack
4.3 Medium Build Private Store For Woocommerce Plugin build-private-store-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-22731 Patchstack
6.1 Medium Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting WpRently | WordPress plugin <= 2.2.1 - Reflected Cross-Site Scripting No login needed ≤ 2.2.1 CVE-2024-12412 Wordfence
4.3 Medium Unlimited Theme Addon For Elementor and WooCommerce Plugin unlimited-theme-addons Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.2.2 CVE-2024-12116 Wordfence
5.4 Medium Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups Plugin coupon-x-discount-pop-up Broken Access Control Missing Authorization ≤ 1.3.5 CVE-2024-12204 Wordfence
6.5 Medium Free WooCommerce Theme 99fy Extension Plugin 99fy-core Cross-Site Scripting ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-22801 Patchstack
6.5 Medium Advanced Product Information for WooCommerce Plugin woo-advanced-product-information Cross-Site Scripting ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-22803 Patchstack
6.5 Medium PDF Catalog Woocommerce Plugin pdf-catalog-woocommerce Cross-Site Scripting ≤ 2.0 Fixed in 3.0 CVE-2025-22809 Patchstack
6.5 Medium S3Player – WooCommerce & Elementor Integration Plugin drm-protected-video-streaming Cross-Site Scripting ≤ 4.2.1 CVE-2025-22818 Patchstack
6.1 Medium Pósturinn\'s Shipping with WooCommerce Plugin posturinn Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.3.1 CVE-2024-11815 Wordfence
6.1 Medium Woocommerce check pincode/zipcode for shipping Plugin woocommerce-check-pincode-zipcode-for-shipping Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 2.0.4 CVE-2024-12218 Wordfence
4.3 Medium MIMO Woocommerce Order Tracking Plugin mimo-woocommerce-order-tracking Broken Access Control Missing Authorization to Limited Settings Update ≤ 1.0.2 CVE-2024-5769 Wordfence
6.1 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross-Site Scripting via dvsfw_bulk_label_url Parameter No login needed ≤ 2.1.7 CVE-2024-12222 Wordfence
6.1 Medium Shipping via Planzer for WooCommerce Plugin wc-planzer-shipping Cross-Site Scripting Reflected Cross-Site Scripting via processed-ids No login needed ≤ 1.0.25 CVE-2024-12337 Wordfence
5.3 Medium Allada T-shirt Designer for Woocommerce Plugin allada-tshirt-designer-for-woocommerce Broken Access Control No login needed ≤ 1.1 CVE-2025-22363 Patchstack
4.3 Medium Hide Category by User Role for WooCommerce Plugin hide-category-by-user-role-for-woocommerce Broken Access Control ≤ 2.1.1 Fixed in 2.2 CVE-2024-56272 Patchstack
4.3 Medium Aurum - WordPress & WooCommerce Shopping Theme Broken Access Control WordPress & WooCommerce Shopping Theme <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Demo Content Import ≤ 4.0.2 CVE-2024-12781 Wordfence
6.1 Medium Binary MLM Woocommerce Plugin woo-binary-mlm Cross-Site Scripting Reflected Cross-Site Scripting via 'page' No login needed ≤ 2.0 CVE-2024-12384 Wordfence
6.1 Medium WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket Plugin woocommerce-digital-content-delivery-with-drm-flickrocket Cross-Site Scripting FlickRocket <= 4.75 - Reflected Cross-Site Scripting No login needed ≤ 4.75 CVE-2024-12438 Wordfence
6.1 Medium Binary MLM Woocommerce Plugin woo-binary-mlm Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.0 CVE-2024-12383 Wordfence
6.1 Medium Store credit / Gift cards for woocommerce Plugin store-credit-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.49.46 CVE-2024-11369 Wordfence
6.1 Medium Compare Products for WooCommerce Plugin woocommerce-compare-products Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.1 CVE-2024-12435 Wordfence
6.1 Medium Bizapp for WooCommerce Plugin bizapp-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.8 CVE-2024-11378 Wordfence
6.1 Medium WooCommerce HSS Extension for Streaming Video Plugin woocommerce-hss-extension-for-streaming-video Cross-Site Scripting Reflected Cross-Site Scripting via videolink Parameter No login needed ≤ 3.31 CVE-2024-12214 Wordfence
6.4 Medium Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce Plugin formaloo-form-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1.3.2 CVE-2024-11934 Wordfence
6.5 Medium Putler Connector for WooCommerce Plugin woocommerce-putler-connector Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.12.0 Fixed in 2.13.0 CVE-2023-40327 Patchstack
4.3 Medium Metorik – Reports & Email Automation for WooCommerce Plugin metorik-helper Cross-Site Request Forgery No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-38691 Patchstack
5.3 Medium CoCart – Headless ecommerce Plugin cart-rest-api-for-woocommerce Broken Access Control Headless ecommerce plugin <= 3.11.2 - Broken Access Control No login needed ≤ 3.11.2 Fixed in 3.12.0 CVE-2023-47241 Patchstack
6.5 Medium Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Broken Access Control Sales Countdown Timer & Discount for WooCommerce plugin <= 2.16.0 - Arbitrary Content Deletion No login needed ≤ 2.16.0 Fixed in 2.17.0 CVE-2023-47180 Patchstack
5.3 Medium YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Broken Access Control No login needed ≤ 4.2.0 Fixed in 4.2.1 CVE-2023-46635 Patchstack
4.3 Medium WowStore Plugin product-blocks Broken Access Control Gutenberg WooCommerce Blocks plugin <= 2.7.8 - Broken Access Control No login needed ≤ 2.7.8 Fixed in 3.0.0 CVE-2023-45271 Patchstack
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control ≤ 5.36.0 Fixed in 5.36.1 CVE-2023-45101 Patchstack
4.3 Medium WooCommerce Subscriptions Plugin woocommerce-subscriptions Broken Access Control < 5.8.0 Fixed in 5.8.0 CVE-2023-50850 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only