WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 801–850 of 2,122 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Premmerce Wholesale Pricing for WooCommerce | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 1.1.10 |
CVE-2025-12411 |
Wordfence | |
| 4.3 Medium | Order Export & Order Import for WooCommerce | Broken Access Control |
≤ 2.6.7 Fixed in 2.6.8 |
CVE-2025-64382 |
Patchstack | |
| 6.5 Medium | Booster for WooCommerce | Cross-Site Scripting |
≤ 7.3.2 Fixed in 7.4.0 |
CVE-2025-64380 |
Patchstack | |
| 4.3 Medium | Booster for WooCommerce | Broken Access Control |
≤ 7.4.0 Fixed in 7.5.0 |
CVE-2025-64379 |
Patchstack | |
| 4.3 Medium | WooCommerce PDF Invoice Builder | Broken Access Control |
≤ 1.2.150 Fixed in 1.2.151 |
CVE-2025-64269 |
Patchstack | |
| 4.3 Medium | WooCommerce Ultimate Points And Rewards | Information Disclosure Sensitive Data Exposure |
≤ 2.10.2 Fixed in 2.10.3 |
CVE-2025-64267 |
Patchstack | |
| 7.5 High | Payment Plugins Braintree For WooCommerce | Broken Access Control Missing Authorization to Payment Token Exposure and Transaction Fraud No login needed |
≤ 3.2.78 |
CVE-2025-12903 |
Wordfence | |
| 4.3 Medium | Wishlist and Save for later for Woocommerce | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion |
≤ 1.1.22 |
CVE-2025-12087 |
Wordfence | |
| 5.3 Medium | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings | Price Manipulation All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass No login needed |
≤ 1.1.27 |
CVE-2025-12788 |
Wordfence | |
| 5.3 Medium | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings | Broken Access Control All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation No login needed |
≤ 1.1.27 |
CVE-2025-12787 |
Wordfence | |
| 5.3 Medium | Make Email Customizer for WooCommerce | Broken Access Control Subscriber+ Arbitrary Options Update No login needed |
≤ 1.0.6 |
CVE-2025-11237 |
WPScan | |
| 6.4 Medium | Woocommerce – Products By Custom Tax | Cross-Site Scripting Products By Custom Tax <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.2 |
CVE-2025-11821 |
Wordfence | |
| 4.3 Medium | USB Qr Code Scanner For Woocommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.0 |
CVE-2025-12588 |
Wordfence | |
| 5.3 Medium | Flexible Refund and Return Order for WooCommerce | Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Refund Status Update No login needed |
≤ 1.0.42 |
CVE-2025-12621 |
Wordfence | |
| 7.1 High | Booster for WooCommerce | Cross-Site Scripting No login needed |
≤ 7.2.5 Fixed in 7.2.6 |
CVE-2025-64196 |
Patchstack | |
| 7.5 High | WPC Product Options for WooCommerce | Local File Inclusion |
≤ 3.1.3 Fixed in 3.1.3 |
CVE-2025-60248 |
Patchstack | |
| 6.5 Medium | Bux Woocommerce | Broken Access Control No login needed |
≤ 1.2.3 |
CVE-2025-60247 |
Patchstack | |
| 9.8 Critical | Selling Commander for WooCommerce | Privilege Escalation No login needed |
≤ 1.2.46 |
CVE-2025-60243 |
Patchstack | |
| 10.0 Critical | Support Ticket System for WooCommerce (Premium) | Arbitrary File Upload No login needed |
≤ 2.0.7 |
CVE-2025-60235 |
Patchstack | |
| 10.0 Critical | Custom User Registration Fields for WooCommerce | Arbitrary File Upload No login needed |
≤ 2.1.2 |
CVE-2025-60207 |
Patchstack | |
| 7.5 High | WooCommerce Store Toolkit | Local File Inclusion No login needed |
≤ 2.4.3 Fixed in 2.4.4 |
CVE-2025-60204 |
Patchstack | |
| 7.5 High | Store Exporter | Local File Inclusion No login needed |
≤ 2.7.6 Fixed in 2.7.7 |
CVE-2025-60203 |
Patchstack | |
| 7.5 High | Premmerce Product Search for WooCommerce | Local File Inclusion No login needed |
≤ 2.2.4 Fixed in 2.2.5 |
CVE-2025-60194 |
Patchstack | |
| 7.5 High | Premmerce Wholesale Pricing for WooCommerce | Local File Inclusion No login needed |
≤ 1.1.10 Fixed in 1.1.11 |
CVE-2025-60192 |
Patchstack | |
| 7.5 High | Premmerce Wishlist for WooCommerce | Local File Inclusion No login needed |
≤ 1.1.10 Fixed in 1.1.11 |
CVE-2025-60191 |
Patchstack | |
| 7.5 High | PoloPag – Pix Automático para Woocommerce | Local File Inclusion Pix Automático para Woocommerce plugin <= 2.0.9 - Local File Inclusion No login needed |
≤ 2.0.9 Fixed in 3.0.0 |
CVE-2025-60189 |
Patchstack | |
| 7.1 High | Booking and Rental Manager | Cross-Site Scripting No login needed |
≤ 2.5.3 Fixed in 2.5.4 |
CVE-2025-49904 |
Patchstack | |
| 9.1 Critical | Dynamic Pricing With Discount Rules for WooCommerce | Remote Code Execution Arbitrary Code Execution |
≤ 4.5.9 Fixed in 4.5.10 |
CVE-2025-47588 |
Patchstack | |
| 4.3 Medium | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Broken Access Control Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending |
≤ 3.6.4.1 |
CVE-2025-12469 |
Wordfence | |
| 5.3 Medium | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Information Disclosure Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure No login needed |
≤ 3.6.4.1 |
CVE-2025-12468 |
Wordfence | |
| 4.3 Medium | Import Export For WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 1.6.2 |
CVE-2025-12389 |
Wordfence | |
| 7.5 High | Crypto Payment Gateway with Payeer for WooCommerce | Price Manipulation Unauthenticated Payment Bypass No login needed |
≤ 1.0.3 |
CVE-2025-11890 |
Wordfence | |
| 4.3 Medium | Smart Coupons for WooCommerce | Broken Access Control |
≤ 2.2.3 Fixed in 2.2.4 |
CVE-2025-64358 |
Patchstack | |
| 7.5 High | WPC Name Your Price for WooCommerce | Broken Access Control Unauthenticated Price Alteration No login needed |
≤ 2.1.9 |
CVE-2025-12115 |
Wordfence | |
| 8.6 High | WooCommerce Designer Pro | Path Traversal Unauthenticated Arbitrary File Read No login needed |
≤ 1.9.28 |
CVE-2025-10897 |
Wordfence | |
| 4.3 Medium | Premmerce Product Search for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 2.2.4 Fixed in 2.2.5 |
CVE-2025-64290 |
Patchstack | |
| 5.9 Medium | Premmerce Product Search for WooCommerce | Cross-Site Scripting |
≤ 2.2.7 |
CVE-2025-64289 |
Patchstack | |
| 5.4 Medium | Premmerce Wholesale Pricing for WooCommerce | Broken Access Control |
≤ 1.1.10 Fixed in 1.1.11 |
CVE-2025-64285 |
Patchstack | |
| 5.9 Medium | Email Template Customizer for WooCommerce | Cross-Site Scripting |
≤ 1.2.17 Fixed in 1.2.18 |
CVE-2025-64200 |
Patchstack | |
| 5.3 Medium | WooCommerce | Information Disclosure Sensitive Information Exposure No login needed |
≤ 7.8.2 |
CVE-2023-7320 |
Wordfence | |
| 5.9 Medium | WooCommerce | Cross-Site Scripting |
≤ 10.0.2 Fixed in 10.0.3 |
CVE-2025-49042 |
Patchstack | |
| 5.3 Medium | Facebook for WooCommerce | Broken Access Control Broken Access Control to Notice Dismissal No login needed |
≤ 3.5.7 Fixed in 3.5.8 |
CVE-2025-64296 |
Patchstack | |
| 7.5 High | HUSKY – Products Filter Professional for WooCommerce | SQL Injection Products Filter Professional for WooCommerce <= 1.3.7.1 - Unauthenticated SQL Injection via `phrase` Parameter No login needed |
≤ 1.3.7.1 |
CVE-2025-11735 |
Wordfence | |
| 7.1 High | NikanWP WooCommerce Reporting | Cross-Site Request Forgery No login needed |
≤ 1.0.0 Fixed in 3.0.0 |
CVE-2025-62957 |
Patchstack | |
| 4.3 Medium | Open Close WooCommerce Store | Broken Access Control |
≤ 5.0.0 |
CVE-2025-62935 |
Patchstack | |
| 5.4 Medium | Conversios.io | Broken Access Control |
≤ 7.2.13 Fixed in 7.2.14 |
CVE-2025-62925 |
Patchstack | |
| 6.5 Medium | WPC Smart Messages for WooCommerce | Cross-Site Scripting |
≤ 4.2.8 Fixed in 4.2.9 |
CVE-2025-62903 |
Patchstack | |
| 4.3 Medium | Premmerce Brands for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 1.2.13 Fixed in 1.2.14 |
CVE-2025-62890 |
Patchstack | |
| 6.4 Medium | The7 — Ultimate WordPress & WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'the7_fancy_title_css' |
≤ 12.9.1 |
CVE-2025-11897 |
Wordfence | |
| 8.8 High | Simple Registration for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Role Request Approval No login needed |
≤ 1.5.8 |
CVE-2025-12095 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.