WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 901–950 of 2,136 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 19 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Appy Pie Connect for WooCommerce Plugin appy-pie-connect-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via reset_user_password No login needed ≤ 1.1.2 CVE-2025-9286 Wordfence
6.4 Medium Big Post Shipping for WooCommerce Plugin woo-bigpost-shipping Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.2 CVE-2025-10191 Wordfence
10.0 Critical WooCommerce Designer Pro Plugin wc-designer-pro Arbitrary File Upload No login needed ≤ 1.9.24 CVE-2025-60219 Patchstack
7.1 High GST for WooCommerce Plugin gst-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-60173 Patchstack
7.1 High Conditional Cart Messages for WooCommerce – YourPlugins.com Plugin yourplugins-wc-conditional-cart-notices Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.10 CVE-2025-60171 Patchstack
4.3 Medium Nota Fiscal Eletrônica WooCommerce Plugin nota-fiscal-eletronica-woocommerce Broken Access Control ≤ 3.4.0.9 Fixed in 3.4.1.0 CVE-2025-60159 Patchstack
5.9 Medium Nota Fiscal Eletrônica WooCommerce Plugin nota-fiscal-eletronica-woocommerce Cross-Site Scripting ≤ 3.4.0.9 Fixed in 3.4.1.0 CVE-2025-60158 Patchstack
6.5 Medium Quantities and Units for WooCommerce Plugin quantities-and-units-for-woocommerce Cross-Site Scripting ≤ 1.0.13 CVE-2025-58917 Patchstack
2.7 Low ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution Plugin Broken Access Control All in One WooCommerce Solution <= 4.8.3 - Insufficient Authorization to Authenticated (Editor+) Settings Update ≤ 4.8.3 CVE-2025-10173 Wordfence
9.8 Critical MultiLoca - WooCommerce Multi Locations Inventory Management Plugin Broken Access Control WooCommerce Multi Locations Inventory Management <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Options Update via 'wcmlim_settings_ajax_handler' No login needed ≤ 4.2.8 CVE-2025-9054 Wordfence
9.8 Critical Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) Plugin Arbitrary File Upload Uni CPO (Premium) <= 4.9.55 - Unauthenticated Arbitrary File Upload via 'uni_cpo_upload_file' No login needed ≤ 4.9.55 CVE-2025-10412 Wordfence
4.3 Medium Payrexx Payment Gateway for WooCommerce Plugin woo-payrexx-gateway Broken Access Control ≤ 3.1.5 Fixed in 3.1.6 CVE-2025-59559 Patchstack
6.5 Medium Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Cross-Site Scripting ≤ 3.0.7 Fixed in 3.0.8 CVE-2025-59565 Patchstack
5.9 Medium CashBill.pl – Płatności WooCommerce Plugin cashbill-payment-method Cross-Site Scripting Płatności WooCommerce Plugin <= 3.2.1 - Cross Site Scripting (XSS) ≤ 3.2.1 Fixed in 3.3.0 CVE-2025-53455 Patchstack
5.9 Medium Sales Count Manager for WooCommerce Plugin wc-sales-count-manager Cross-Site Scripting ≤ 2.6 CVE-2025-57904 Patchstack
5.9 Medium WooCommerce Additional Fees On Checkout (Free) Plugin woo-additional-fees-on-checkout-wordpress Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-57903 Patchstack
4.3 Medium AgreeMe Checkboxes For WooCommerce Plugin agreeme-checkboxes-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-57905 Patchstack
5.9 Medium Product Time Countdown for WooCommerce Plugin product-countdown-for-woocommerce Cross-Site Scripting ≤ 1.6.5 CVE-2025-57908 Patchstack
4.3 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Request Forgery No login needed ≤ 3.0.2 Fixed in 3.1.0 CVE-2025-57914 Patchstack
4.3 Medium Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration Broken Access Control ≤ 2.4.8 CVE-2025-57917 Patchstack
5.3 Medium Envíos Coordinadora Woocommerce Plugin coordinadora Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.32 CVE-2025-57922 Patchstack
6.5 Medium WPB Quick View for WooCommerce Plugin woocommerce-lightbox Cross-Site Scripting ≤ 2.1.8 Fixed in 2.2 CVE-2025-57967 Patchstack
4.3 Medium Helpdesk Support Ticket System for WooCommerce Plugin support-ticket-system-for-woocommerce Broken Access Control ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-57972 Patchstack
7.1 High Flexible PDF Invoices for WooCommerce & Plugin flexible-invoices Cross-Site Request Forgery No login needed ≤ 6.0.13 Fixed in 6.0.14 CVE-2025-57977 Patchstack
6.5 Medium Quick View for WooCommerce Plugin woo-quickview Cross-Site Scripting ≤ 2.2.16 Fixed in 2.2.17 CVE-2025-58228 Patchstack
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control No login needed ≤ 2.10.0 Fixed in 2.11.0 CVE-2025-58247 Patchstack
5.3 Medium Estonian Shipping Methods for WooCommerce Plugin estonian-shipping-methods-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 1.7.2 CVE-2025-58656 Patchstack
8.5 High Perfect Brands for WooCommerce Plugin perfect-woocommerce-brands SQL Injection ≤ 3.6.2 Fixed in 3.6.3 CVE-2025-58686 Patchstack
5.3 Medium Cecabank WooCommerce Plugin cecabank-woocommerce Broken Access Control No login needed ≤ 0.3.4 Fixed in 0.3.5 CVE-2025-58685 Patchstack
6.5 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Cross-Site Scripting ≤ 2.0.92 Fixed in 2.1.00 CVE-2025-58702 Patchstack
4.9 Medium PagBank / PagSeguro Connect para WooCommerce Plugin pagbank-connect SQL Injection Authenticated (Shop Manager+) SQL Injection ≤ 4.44.3 CVE-2025-10142 Wordfence
6.5 Medium Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net Plugin peachpay-for-woocommerce SQL Injection Authenticated (Contributor+) SQL Injection via order_by Parameter ≤ 1.117.5 CVE-2025-9463 Wordfence
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-58985 Patchstack
7.1 High WooCommerce Booking Bundle Hours Plugin woo-booking-bundle-hours Cross-Site Request Forgery No login needed ≤ 0.7.4 Fixed in 0.7.5 CVE-2025-58991 Patchstack
9.3 Critical WooCommerce Ultimate Gift Card Plugin woocommerce-ultimate-gift-card SQL Injection No login needed ≤ 2.9.6 Fixed in 2.9.7 CVE-2025-47569 Patchstack
7.1 High WooCommerce Photo Reviews Plugin woocommerce-photo-reviews Cross-Site Scripting No login needed ≤ 1.3.13 CVE-2025-47570 Patchstack
4.9 Medium ELEX WooCommerce Google Shopping (Google Product Feed) Plugin elex-woocommerce-google-product-feed-plugin-basic SQL Injection Authenticated (Admin+) SQL Inejction ≤ 1.4.3 CVE-2025-10046 Wordfence
7.5 High WooCommerce Payment Gateway for Saferpay Plugin woocommerce-payment-gateway-for-saferpay Path Traversal No login needed ≤ 0.4.9 CVE-2025-48317 Patchstack
6.5 Medium Woocommerce Gifts Product Plugin woo-gift-product Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-58878 Patchstack
6.5 Medium Woocommerce Notify Updated Product Plugin woocommerce-notify-updated-product Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-58856 Patchstack
4.3 Medium WooCommerce Single Page Checkout Plugin woo-single-page-checkout Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-58804 Patchstack
4.3 Medium TrustMate.io – WooCommerce integration Plugin trustmate-io-integration-for-woocommerce Cross-Site Request Forgery WooCommerce integration plugin <= 1.16.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.16.0 CVE-2025-58802 Patchstack
4.3 Medium Custom WooCommerce Checkout Fields Editor Plugin add-fields-to-checkout-page-woocommerce Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-58799 Patchstack
7.6 High License Manager for WooCommerce Plugin license-manager-for-woocommerce SQL Injection ≤ 3.0.12 Fixed in 3.0.13 CVE-2025-58788 Patchstack
5.3 Medium PeachPay Payments Plugin peachpay-for-woocommerce Broken Access Control No login needed ≤ 1.117.4 Fixed in 1.117.5 CVE-2025-58634 Patchstack
4.3 Medium Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Broken Access Control ≤ 4.1.0 Fixed in 4.2.0 CVE-2025-58599 Patchstack
6.6 Medium Klarna Order Management for WooCommerce Plugin klarna-order-management-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 1.9.8 Fixed in 1.9.9 CVE-2025-58598 Patchstack
8.1 High Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary File Upload Unauthenticated Double Extension Arbitrary File Upload No login needed ≤ 7.2.4 CVE-2024-13342 Wordfence
7.7 High WooCommerce csv import export Plugin extendons-eo-wooimport-export Arbitrary File Deletion ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-54029 Patchstack
5.9 Medium Risk Free Cash On Delivery (COD) – WooCommerce Plugin risk-free-cash-on-delivery-cod-woocommerce Cross-Site Scripting WooCommerce plugin <= 1.0.4 - Cross Site Scripting (XSS) ≤ 1.0.4 CVE-2025-48358 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only