WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 801–850 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 17 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium DN Shipping by Weight for WooCommerce Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.2 Fixed in 1.2 CVE-2024-11842 WPScan
5.3 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control Missing Authorization No login needed ≤ 2.0.00 CVE-2024-12413 Wordfence
6.5 Medium Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking Plugin tourfic SQL Injection Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 - Authenticated (Subscriber+) SQL Injection ≤ 2.15.3 CVE-2024-12032 Wordfence
4.3 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control Missing Authorization to Authenticated (Subscriber+) Logo Deletion ≤ 5.4.0 CVE-2024-12210 Wordfence
6.5 Medium ELEX WooCommerce Dynamic Pricing and Discounts Plugin elex-woocommerce-dynamic-pricing-and-discounts Broken Access Control Missing Authorization No login needed ≤ 2.1.7 CVE-2024-12266 Wordfence
6.4 Medium One Click Upsell Funnel for WooCommerce Plugin woo-one-click-upsell-funnel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wps_wocuf_pro_yes Shortcode ≤ 3.4.9 CVE-2024-11938 Wordfence
6.4 Medium Spoki – Chat Buttons and WooCommerce Notifications Plugin spoki Cross-Site Scripting Chat Buttons and WooCommerce Notifications <= 2.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.15.15 CVE-2024-11893 Wordfence
6.1 Medium WooCommerce Additional Fees On Checkout (Free) Plugin woo-additional-fees-on-checkout-wordpress Cross-Site Scripting Reflected Cross-Site Scripting via 'number' No login needed ≤ 1.4.7 CVE-2024-12395 Wordfence
6.1 Medium SMS for WooCommerce Plugin wc-sms Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 2.8.1 CVE-2024-12220 Wordfence
6.1 Medium Dreamfox Media Payment gateway per Product for Woocommerce Plugin woocommerce-product-payments Broken Access Control No login needed ≤ 3.5.6 Fixed in 3.5.9 CVE-2024-55996 Patchstack
5.4 Medium WooCommerce Basic Ordernumbers Plugin woocommerce-basic-ordernumbers Broken Access Control ≤ 1.4.4 CVE-2024-55992 Patchstack
5.3 Medium Spreadr Woocommerce Plugin spreadr-for-woocomerce Broken Access Control No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-56009 Patchstack
6.4 Medium Posts and Products Views for WooCommerce Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1 CVE-2024-12448 Wordfence
6.4 Medium WooCommerce Cart Count Shortcode Plugin woo-cart-count-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2024-12517 Wordfence
6.5 Medium Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification Plugin elite-notification Cross-Site Scripting 1.5 CVE-2024-54241 Patchstack
5.3 Medium Brands for WooCommerce Plugin brands-for-woocommerce Broken Access Control No login needed ≤ 3.8.2.2 Fixed in 3.8.2.3 CVE-2023-44149 Patchstack
5.3 Medium BitPay Checkout for WooCommerce Plugin bitpay-checkout-for-woocommerce Broken Access Control No login needed ≤ 4.1.0 Fixed in 5.0.0 CVE-2023-41803 Patchstack
6.5 Medium Woocommerce Support System Plugin wc-support-system Cross-Site Request Forgery No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2023-41686 Patchstack
5.4 Medium Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Cross-Site Request Forgery ≤ 5.16.1 Fixed in 5.16.2 CVE-2023-41671 Patchstack
4.3 Medium Category Slider for WooCommerce Plugin woo-category-slider-grid Broken Access Control ≤ 1.4.15 Fixed in 1.4.16 CVE-2023-41132 Patchstack
4.3 Medium HUSKY Plugin woocommerce-products-filter Broken Access Control ≤ 1.3.4.2 Fixed in 1.3.4.3 CVE-2023-40334 Patchstack
5.4 Medium Easyship WooCommerce Shipping Rates Plugin easyship-woocommerce-shipping-rates Broken Access Control ≤ 0.9.0 Fixed in 0.9.1 CVE-2023-37989 Patchstack
6.5 Medium WooCommerce Product Stock Alert Plugin woocommerce-product-stock-alert Broken Access Control No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2023-37971 Patchstack
5.3 Medium Checkout with Zelle on Woocommerce Plugin wc-zelle Broken Access Control No login needed ≤ 3.1 Fixed in 3.1.1 CVE-2023-37969 Patchstack
5.3 Medium YITH WooCommerce Waiting List Plugin yith-woocommerce-waiting-list Broken Access Control No login needed ≤ 2.13.0 Fixed in 2.13.1 CVE-2023-36506 Patchstack
5.4 Medium Change WooCommerce Add To Cart Button Text Plugin change-woocommerce-add-to-cart-button-text Broken Access Control ≤ 1.3 CVE-2023-34376 Patchstack
5.3 Medium WooCommerce Predictive Search Plugin woocommerce-predictive-search Broken Access Control No login needed ≤ 5.8.0 Fixed in 5.8.1 CVE-2023-32963 Patchstack
5.3 Medium APIExperts Square for WooCommerce Plugin woosquare Broken Access Control No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2022-47182 Patchstack
4.3 Medium Printful Integration for WooCommerce Plugin printful-shipping-for-woocommerce Cross-Site Request Forgery ≤ 2.2.3 Fixed in 2.2.4 CVE-2022-47168 Patchstack
4.3 Medium ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Plugin woo-alidropship Broken Access Control Broken Access Control + CSRF ≤ 1.0.21 Fixed in 1.0.22 CVE-2022-46811 Patchstack
4.3 Medium Stock Sync for WooCommerce Plugin stock-sync-for-woocommerce Broken Access Control ≤ 2.3.2 Fixed in 2.4.0 CVE-2022-46807 Patchstack
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Cross-Site Request Forgery CSRF Plugin Settings Reset No login needed ≤ 4.7.2 Fixed in 4.7.3 CVE-2022-46795 Patchstack
6.1 Medium MyParcel Plugin woocommerce-myparcel Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.24.1 CVE-2024-9608 Wordfence
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Missing Authorization to Authenticated (Subscriber+) WooCommerce Installation ≤ 2.1.12 CVE-2024-11911 Wordfence
6.5 Medium Coupon Affiliates – Affiliate Plugin for WooCommerce Plugin woo-coupon-usage Arbitrary Shortcode Execution Affiliate Plugin for WooCommerce <= 5.16.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed ≤ 5.16.7.1 CVE-2024-12421 Wordfence
6.1 Medium Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.2.1 CVE-2024-11809 Wordfence
6.1 Medium Seraphinite Bulk Discounts for WooCommerce Plugin seraphinite-discount-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.6 CVE-2024-12160 Wordfence
4.4 Medium NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Plugin notificationx Cross-Site Scripting Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.9.3 CVE-2024-11727 Wordfence
5.3 Medium Web3 Cryptocurrency Payments by DePay for WooCommerce Plugin Broken Access Control Missing Authorization to Information Exposure No login needed ≤ 2.12.17 CVE-2024-12265 Wordfence
6.1 Medium WPC Order Notes for WooCommerce Plugin woo-order-notes Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.5.2 CVE-2024-12004 Wordfence
4.3 Medium Minimum and Maximum Quantity for WooCommerce Plugin min-and-max-quantity-for-woocommerce Broken Access Control ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-54227 Patchstack
5.4 Medium Cost of Goods for WooCommerce Plugin cost-of-goods-for-woocommerce Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2023-23868 Patchstack
4.3 Medium PayPal Brasil para WooCommerce Plugin paypal-brasil-para-woocommerce Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2023-25026 Patchstack
5.3 Medium Stamped.io Product Reviews & UGC for WooCommerce Plugin stampedio-product-reviews Broken Access Control No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2023-30479 Patchstack
4.3 Medium Smart WooCommerce Search Plugin smart-woocommerce-search Broken Access Control ≤ 2.5.0 Fixed in 2.5.1 CVE-2023-30783 Patchstack
6.5 Medium Ni WooCommerce Sales Report Plugin ni-woocommerce-sales-report Broken Access Control ≤ 3.7.3 Fixed in 3.7.4 CVE-2023-32299 Patchstack
5.4 Medium Mini Cart Drawer For WooCommerce Plugin woo-mini-cart-drawer Broken Access Control No login needed ≤ 4.0.0 Fixed in 4.0.1 CVE-2023-47694 Patchstack
5.3 Medium PayTR Taksit Tablosu Plugin paytr-taksit-tablosu-woocommerce Broken Access Control No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2023-47847 Patchstack
5.3 Medium Importify (Dropshipping WooCommerce) Plugin importify Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2023-49194 Patchstack
5.4 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control ≤ 5.0.2 Fixed in 5.0.3 CVE-2023-50899 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only