WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 851–900 of 2,136 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 18 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Scripting ≤ 2.2.7 CVE-2025-64289 Patchstack
5.4 Medium Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Broken Access Control ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-64285 Patchstack
5.9 Medium Email Template Customizer for WooCommerce Plugin email-template-customizer-for-woo Cross-Site Scripting ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-64200 Patchstack
5.3 Medium WooCommerce Plugin woocommerce Information Disclosure Sensitive Information Exposure No login needed ≤ 7.8.2 CVE-2023-7320 Wordfence
5.9 Medium WooCommerce Plugin woocommerce Cross-Site Scripting ≤ 10.0.2 Fixed in 10.0.3 CVE-2025-49042 Patchstack
5.3 Medium Facebook for WooCommerce Plugin facebook-for-woocommerce Broken Access Control Broken Access Control to Notice Dismissal No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-64296 Patchstack
7.5 High HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter SQL Injection Products Filter Professional for WooCommerce <= 1.3.7.1 - Unauthenticated SQL Injection via `phrase` Parameter No login needed ≤ 1.3.7.1 CVE-2025-11735 Wordfence
7.1 High NikanWP WooCommerce Reporting Plugin wc-reports-lite Cross-Site Request Forgery No login needed ≤ 1.0.0 Fixed in 3.0.0 CVE-2025-62957 Patchstack
4.3 Medium Open Close WooCommerce Store Plugin woc-open-close Broken Access Control ≤ 5.0.0 CVE-2025-62935 Patchstack
5.4 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control ≤ 7.2.13 Fixed in 7.2.14 CVE-2025-62925 Patchstack
6.5 Medium WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Cross-Site Scripting ≤ 4.2.8 Fixed in 4.2.9 CVE-2025-62903 Patchstack
4.3 Medium Premmerce Brands for WooCommerce Plugin premmerce-woocommerce-brands Cross-Site Request Forgery No login needed ≤ 1.2.13 Fixed in 1.2.14 CVE-2025-62890 Patchstack
6.4 Medium The7 — Ultimate WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'the7_fancy_title_css' ≤ 12.9.1 CVE-2025-11897 Wordfence
8.8 High Simple Registration for WooCommerce Plugin woocommerce-simple-registration Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Role Request Approval No login needed ≤ 1.5.8 CVE-2025-12095 Wordfence
2.7 Low ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution Plugin shopengine Broken Access Control All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update ≤ 4.8.4 CVE-2025-11888 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.4 CVE-2025-11823 Wordfence
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.1.4 CVE-2025-10861 Wordfence
6.1 Medium VNPAY for Woocommerce Plugin vnpay-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-12017 Wordfence
6.4 Medium Simple Excel Pricelist for WooCommerce Plugin simple-excel-pricelist-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.13 CVE-2025-12096 Wordfence
9.8 Critical WooCommerce Designer Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.9.26 CVE-2025-6440 Wordfence
7.6 High Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free SQL Injection ≤ 4.6.8 Fixed in 4.6.9 CVE-2025-62015 Patchstack
8.8 High Product Table For WooCommerce Plugin product-table-for-woocommerce PHP Object Injection ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-62008 Patchstack
7.1 High SUMO Memberships for WooCommerce Plugin sumomemberships Cross-Site Request Forgery No login needed ≤ 7.8.0 Fixed in 7.8.0 CVE-2025-62005 Patchstack
8.8 High SUMO Memberships for WooCommerce Plugin sumomemberships Privilege Escalation ≤ 7.8.0 Fixed in 7.9.0 CVE-2025-60222 Patchstack
8.8 High WooCommerce Registration Fields Plugin - Custom Signup Fields Plugin extendons-registration-fields Privilege Escalation Custom Signup Fields plugin <= 3.2.3 - Privilege Escalation ≤ 3.2.3 CVE-2025-60211 Patchstack
5.8 Medium ShopMagic Plugin shopmagic-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 4.5.6 Fixed in 4.5.7 CVE-2025-59578 Patchstack
7.1 High Easy Woocommerce Customizer Plugin easy-woocommerce-customizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-59006 Patchstack
6.5 Medium WooCommerce Orders & Customers Exporter Plugin woocommerce-orders-ei Broken Access Control ≤ 5.4 CVE-2025-53424 Patchstack
7.1 High WhatsApp Chat for WordPress and WooCommerce Plugin tw-whatsapp-chat-rotator Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2025-53422 Patchstack
7.1 High Woocommerce Envato Affiliates Plugin wooenvato Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2025-53297 Patchstack
6.5 Medium SUMO Memberships for WooCommerce Plugin sumomemberships Broken Access Control Arbitrary Content Deletion ≤ 7.8.0 Fixed in 7.8.0 CVE-2025-52757 Patchstack
7.1 High Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Cross-Site Scripting No login needed ≤ 2.20.0 CVE-2025-52736 Patchstack
7.1 High Robokassa payment gateway for Woocommerce Plugin robokassa Cross-Site Scripting No login needed ≤ 1.8.6 CVE-2025-49958 Patchstack
7.1 High WooCommerce Registration Fields Plugin - Custom Signup Fields Plugin extendons-registration-fields Cross-Site Scripting Custom Signup Fields plugin <= 3.2.3 - Cross Site Scripting (XSS) No login needed ≤ 3.2.3 CVE-2025-49947 Patchstack
7.2 High Wholesale Suite Plugin woocommerce-wholesale-prices Privilege Escalation ≤ 2.2.4.2 Fixed in 2.2.5 CVE-2025-49924 Patchstack
8.6 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.2.23 Fixed in 4.2.24 CVE-2025-49916 Patchstack
7.1 High WooCommerce Vehicle Parts Finder Plugin woo-vehicle-parts-finder Cross-Site Scripting No login needed ≤ 3.7 Fixed in 3.8 CVE-2025-49911 Patchstack
6.5 Medium WPC Countdown Timer for WooCommerce Plugin wpc-countdown-timer Cross-Site Scripting ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-49908 Patchstack
9.8 Critical WooCommerce Vehicle Parts Finder Plugin woo-vehicle-parts-finder PHP Object Injection No login needed ≤ 3.7 Fixed in 3.8 CVE-2025-49380 Patchstack
4.3 Medium Flexible Refund and Return Order for WooCommerce Plugin flexible-refund-and-return-order-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Refund ≤ 1.0.38 CVE-2025-10570 Wordfence
7.5 High PPOM – Product Addons & Custom Fields for WooCommerce Plugin woocommerce-product-addon SQL Injection Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated SQL Injection No login needed ≤ 33.0.15 CVE-2025-11691 Wordfence
9.8 Critical PPOM – Product Addons & Custom Fields for WooCommerce Plugin woocommerce-product-addon Arbitrary File Upload Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated Arbitrary File Upload No login needed ≤ 33.0.15 CVE-2025-11391 Wordfence
5.3 Medium WPC Smart Quick View for WooCommerce Plugin woo-smart-quick-view Broken Access Control Insecure Direct Object Reference to Unauthenticated Private Product Exposure No login needed ≤ 4.2.5 CVE-2025-11741 Wordfence
4.3 Medium WPC Smart Wishlist for WooCommerce Plugin woo-smart-wishlist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Information Exposure ≤ 5.0.4 CVE-2025-11742 Wordfence
8.8 High XStore | Multipurpose WooCommerce Theme Local File Inclusion Authenticated (Subscriber+) Local File Inclusion ≤ 9.5.4 CVE-2025-11746 Wordfence
9.8 Critical WooCommerce Designer Pro Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.9.26 CVE-2025-6439 Wordfence
6.4 Medium Stock History & Reports Manager for WooCommerce Plugin stock-snapshot-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.2 CVE-2025-10167 Wordfence
5.3 Medium WPC Smart Wishlist for WooCommerce Plugin woo-smart-wishlist Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed ≤ 5.0.3 CVE-2025-11518 Wordfence
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via 'id' No login needed ≤ 2.1.3 CVE-2025-10862 Wordfence
7.5 High OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Path Traversal Unauthenticated Arbitrary File Read No login needed < 14 Fixed in 14 CVE-2025-10162 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only