WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 851–900 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 18 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control No login needed ≤ 6.5.0 Fixed in 6.5.1 CVE-2023-51357 Patchstack
6.1 Medium CardGate Payments for WooCommerce Plugin cardgate Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.1 CVE-2024-12257 Wordfence
6.1 Medium 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 Plugin pgall-for-woocommerce Cross-Site Scripting 우커머스 결제 플러그인 <= 5.2.2 - Reflected Cross-Site Scripting via add_query_arg Function No login needed ≤ 5.2.2 CVE-2024-11943 Wordfence
6.1 Medium افزونه پیامک ووکامرس Persian WooCommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.0.5 CVE-2024-10046 Wordfence
6.1 Medium Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.9.2 CVE-2024-11687 Wordfence
6.1 Medium PDF Builder for WooCommerce. Create invoices,packing slips and more Plugin woo-pdf-invoice-builder Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.136 CVE-2024-11276 Wordfence
6.1 Medium Accounting for WooCommerce Plugin accounting-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.6 CVE-2024-11324 Wordfence
6.1 Medium Additional Custom Order Status for WooCommerce Plugin order-status-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.0 CVE-2024-11814 Wordfence
6.1 Medium Quick License Manager – WooCommerce Plugin quick-license-manager Cross-Site Scripting WooCommerce Plugin <= 2.4.17 - Reflected Cross-Site Scripting No login needed ≤ 2.4.17 CVE-2024-11805 Wordfence
6.5 Medium Wallet for WooCommerce Plugin woo-wallet Other Authenticated (Subscriber+) Incorrect Conversion between Numeric Types ≤ 1.5.6 CVE-2024-7747 Wordfence
5.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Authenticated (ShopManager+) Stored Cross-Site Scripting via wcj_product_meta Shortcode ≤ 7.2.3 CVE-2024-9170 Wordfence
6.5 Medium Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 1.9 CVE-2024-10857 Wordfence
6.1 Medium Additional Order Filters for WooCommerce Plugin additional-order-filters-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.21 CVE-2024-11418 Wordfence
6.4 Medium 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 Plugin pgall-for-woocommerce Cross-Site Scripting 우커머스 결제 플러그인 <= 5.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting pafw_instant_payment Shortcode ≤ 5.1.4 CVE-2024-11228 Wordfence
6.1 Medium Wishlist for WooCommerce: Multi Wishlists Per Customer PRO Plugin wish-list-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via wtab Parameter No login needed 3.0.8, 3.0.9, 3.1.0, … CVE-2024-10519 Wordfence
6.1 Medium Checkout with Cash App on WooCommerce Plugin wc-cashapp Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 6.0.2 CVE-2024-9635 Wordfence
6.1 Medium PDF Invoices & Packing Slips Generator for WooCommerce Plugin pdf-invoicing-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2.1 CVE-2024-11361 Wordfence
5.3 Medium Product Table for WooCommerce by CodeAstrology (wooproducttable.com) Plugin woo-product-table Information Disclosure Information Exposure No login needed ≤ 3.5.1 CVE-2024-10813 Wordfence
6.1 Medium Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net Plugin peachpay-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.112.0 CVE-2024-11362 Wordfence
6.1 Medium Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels Plugin wpfunnels Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.5.5 CVE-2024-10792 Wordfence
6.1 Medium Subaccounts for WooCommerce Plugin subaccounts-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.0 CVE-2024-11370 Wordfence
4.3 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 6.0.3 CVE-2024-10365 Wordfence
6.1 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.2.3 CVE-2024-9239 Wordfence
6.1 Medium HUSKY – Products Filter for WooCommerce Plugin Cross-Site Scripting Products Filter for WooCommerce <= 1.3.6.3 - Reflected Cross-Site Scripting via really_curr_tax Parameter No login needed ≤ 1.3.6.3 CVE-2024-11400 Wordfence
5.3 Medium Floating Buttons for WooCommerce Plugin shop-assistant-for-woocommerce-jarvis Broken Access Control No login needed ≤ 2.8.8 Fixed in 2.9.2 CVE-2024-52395 Patchstack
5.3 Medium Google for WooCommerce Plugin google-listings-and-ads Information Disclosure Information Disclosure via Publicly Accessible PHP Info File No login needed ≤ 2.8.6 CVE-2024-10486 Wordfence
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Import Cancellation ≤ 5.61.0 CVE-2024-10614 Wordfence
6.1 Medium PeproDev WooCommerce Receipt Uploader Plugin pepro-bacs-receipt-upload-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.6.9 CVE-2024-8873 Wordfence
5.7 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 6.0.9 CVE-2024-8978 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.0.7 CVE-2024-8961 Wordfence
6.1 Medium Yotpo: Product & Photo Reviews for WooCommerce Plugin yotpo-social-reviews-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.9 CVE-2024-9356 Wordfence
6.1 Medium Product Delivery Date for WooCommerce - Lite Plugin product-delivery-date-for-woocommerce-lite Cross-Site Scripting Lite <= 2.8.0 - Reflected Cross-Site Scripting No login needed ≤ 2.8.0 CVE-2024-10882 Wordfence
4.3 Medium Buy one click WooCommerce Plugin buy-one-click-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Import ≤ 2.2.9 CVE-2024-10854 Wordfence
4.3 Medium Buy one click WooCommerce Plugin buy-one-click-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Order Deletion ≤ 2.2.9 CVE-2024-10853 Wordfence
4.3 Medium Buy one click WooCommerce Plugin buy-one-click-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Export ≤ 2.2.9 CVE-2024-10852 Wordfence
6.1 Medium SysBasics Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via tab Parameter No login needed ≤ 2.7.29 CVE-2024-10837 Wordfence
6.4 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode ≤ 1.0.6.4 CVE-2024-10168 Wordfence
5.3 Medium Video Gallery for WooCommerce Plugin video-wc-gallery Broken Access Control Missing Authorization to Unauthenticated Limited File Deletion No login needed ≤ 1.31 CVE-2024-10535 Wordfence
6.4 Medium XT Floating Cart for WooCommerce Plugin woo-floating-cart-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.8.2 CVE-2024-9178 Wordfence
4.3 Medium Woocommerce Customers Order History Plugin woo-customers-order-history Broken Access Control ≤ 5.2.2 CVE-2024-37201 Patchstack
4.3 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Broken Access Control ≤ 5.3.9 CVE-2024-37203 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 2.7.2 - Broken Access Control No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-38702 Patchstack
5.3 Medium Wholesale Suite Plugin woocommerce-wholesale-prices Broken Access Control No login needed ≤ 2.1.12 Fixed in 2.2.0 CVE-2024-38745 Patchstack
4.3 Medium Waitlist Woocommerce ( Back in stock notifier ) Plugin waitlist-woocommerce Broken Access Control ≤ 2.6 Fixed in 2.6.1 CVE-2024-43134 Patchstack
5.3 Medium Persian WooCommerce Plugin persian-woocommerce Broken Access Control No login needed ≤ 7.1.6 Fixed in 9.0.0 CVE-2024-43219 Patchstack
5.4 Medium WPC Frequently Bought Together for WooCommerce Plugin woo-bought-together Broken Access Control ≤ 7.1.9 Fixed in 7.2.0 CVE-2024-43312 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack
4.3 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control ≤ 5.3.6 Fixed in 5.3.7 CVE-2024-44006 Patchstack
6.5 Medium SIP Reviews Shortcode for WooCommerce Plugin sip-reviews-shortcode-woocommerce SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.2.3 CVE-2024-6479 Wordfence
6.4 Medium SIP Reviews Shortcode for WooCommerce Plugin sip-reviews-shortcode-woocommerce Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting ≤ 1.2.3 CVE-2024-6480 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only