WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 901–950 of 1,255 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Get Quote For Woocommerce – Request A Quote For Woocommerce | Broken Access Control Request A Quote For Woocommerce <= 1.0.0 - Missing Authorization to Unauthenticated Quote PDF and CSV Download No login needed |
≤ 1.0.0 |
CVE-2024-9430 |
Wordfence | |
| 6.4 Medium | Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 4.4.4 |
CVE-2024-9165 |
Wordfence | |
| 5.3 Medium | WooCommerce PDF Invoices & Packing Slips | Broken Access Control No login needed |
≤ 3.8.6 Fixed in 3.8.7 |
CVE-2024-50421 |
Patchstack | |
| 6.4 Medium | SMSAlert - WooCommerce | Cross-Site Scripting WooCommerce <= 3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_subscribe Shortcode |
≤ 3.7.5 |
CVE-2024-10233 |
Wordfence | |
| 4.3 Medium | WPC Smart Messages for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Message Activation/Deactivation |
≤ 4.2.1 |
CVE-2024-10437 |
Wordfence | |
| 6.5 Medium | Envo's Elementor Templates & Widgets for WooCommerce | Cross-Site Scripting |
≤ 1.4.19 Fixed in 1.4.20 |
CVE-2024-50447 |
Patchstack | |
| 6.1 Medium | Extra Product Options Builder for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.2.133 |
CVE-2024-9214 |
Wordfence | |
| 6.3 Medium | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution | Cross-Site Request Forgery The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates No login needed |
≤ 4.2.4 |
CVE-2024-9943 |
Wordfence | |
| 4.3 Medium | HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce | Broken Access Control An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce <= 2.10.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Publication |
≤ 2.10.0 |
CVE-2024-8667 |
Wordfence | |
| 4.3 Medium | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution | Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending |
≤ 4.2.4 |
CVE-2024-9531 |
Wordfence | |
| 5.4 Medium | CartBounty – Save and recover abandoned carts for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 8.2 Fixed in 8.2.1 |
CVE-2024-47634 |
Patchstack | |
| 6.1 Medium | Edit WooCommerce Templates | Cross-Site Scripting Reflected Cross-Site Scripting via page No login needed |
≤ 1.1.2 |
CVE-2024-10049 |
Wordfence | |
| 5.9 Medium | Email Template Customizer for WooCommerce | Cross-Site Scripting |
≤ 1.2.9.1 Fixed in 1.2.9.2 |
CVE-2024-49288 |
Patchstack | |
| 4.3 Medium | Linked Variation for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 1.0.5 Fixed in 2.0.0 |
CVE-2024-48047 |
Patchstack | |
| 6.1 Medium | Persian WooCommerce SMS | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 7.0.2 |
CVE-2024-9213 |
Wordfence | |
| 5.3 Medium | WooCommerce Smart Coupons | Broken Access Control Unauthenticated Coupon Creation No login needed |
< 4.6.5 Fixed in 4.6.5 |
CVE-2020-36841 |
Wordfence | |
| 6.3 Medium | Discount Rules for WooCommerce | Broken Access Control Missing Authorization |
≤ 2.0.2 |
CVE-2020-36834 |
Wordfence | |
| 4.7 Medium | Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons | Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed |
≤ 2.6.5 |
CVE-2024-8541 |
Wordfence | |
| 5.3 Medium | WooCommerce | Content Injection Unauthenticated HTML Injection No login needed |
≤ 9.0.2 |
CVE-2024-9944 |
Wordfence | |
| 4.3 Medium | Order Attachments for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary File Upload |
2.0 – 2.4.1 |
CVE-2024-9756 |
Wordfence | |
| 4.3 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template |
≤ 5.6.11 |
CVE-2024-8913 |
Wordfence | |
| 6.5 Medium | WordPress Comments Import & Export | Path Traversal Authenticated (Author+) Arbitrary File Read via Directory Traversal |
≤ 2.3.7 |
CVE-2024-7514 |
Wordfence | |
| 5.9 Medium | TI WooCommerce Wishlist | SQL Injection Unauthenticated SQL Injection via lang parameters No login needed |
≤ 2.8.2 |
CVE-2024-9156 |
WPScan | |
| 6.1 Medium | Products, Order & Customers Export for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.0.15 |
CVE-2024-9377 |
Wordfence | |
| 6.1 Medium | Maximum Products per User for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.2.8 |
CVE-2024-9205 |
Wordfence | |
| 6.1 Medium | WooCommerce Multilingual & Multicurrency with WPML | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 5.3.7 |
CVE-2024-8629 |
Wordfence | |
| 5.9 Medium | Themify – WooCommerce Product Filter | Cross-Site Scripting |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2024-44046 |
Patchstack | |
| 6.6 Medium | Cities Shipping Zones for WooCommerce | Local File Inclusion |
≤ 1.2.7 Fixed in 1.2.8 |
CVE-2024-47309 |
Patchstack | |
| 4.7 Medium | Checkout Field Editor (Checkout Manager) for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting via render_review_request_notice No login needed |
≤ 2.0.3 |
CVE-2024-8499 |
Wordfence | |
| 6.1 Medium | Quantity Dynamic Pricing & Bulk Discounts for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.8.0 |
CVE-2024-9384 |
Wordfence | |
| 6.1 Medium | Product Delivery Date for WooCommerce – Lite | Cross-Site Scripting Lite <= 2.7.3 - Reflected Cross-Site Scripting No login needed |
≤ 2.7.3 |
CVE-2024-9345 |
Wordfence | |
| 5.4 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Arbitrary Shortcode Execution Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 5.7.34 |
CVE-2024-8254 |
Wordfence | |
| 6.1 Medium | Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More | Cross-Site Scripting Export Products, Export Orders, Export Subscriptions, and More <= 2.7.2.1 - Reflected Cross-Site Scripting No login needed |
≤ 2.7.2.1 |
CVE-2024-8793 |
Wordfence | |
| 5.3 Medium | EU/UK VAT Manager for WooCommerce | Broken Access Control Missing Authorization No login needed |
≤ 2.12.12 |
CVE-2024-9189 |
Wordfence | |
| 6.1 Medium | EU/UK VAT Manager for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.12.12 |
CVE-2024-8788 |
Wordfence | |
| 4.3 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure |
≤ 5.7.34 |
CVE-2024-8771 |
Wordfence | |
| 6.1 Medium | Store Hours for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.3.20 |
CVE-2024-8872 |
Wordfence | |
| 5.3 Medium | Revolut Gateway for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Order Status Update No login needed |
≤ 4.17.3 |
CVE-2024-8678 |
Wordfence | |
| 5.3 Medium | Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred | Broken Access Control Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade No login needed |
≤ 2.7.3 |
CVE-2024-8658 |
Wordfence | |
| 6.4 Medium | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 2.9.7 |
CVE-2024-8668 |
Wordfence | |
| 5.3 Medium | HUSKY – Products Filter Professional for WooCommerce | Broken Access Control Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe No login needed |
≤ 1.3.6.1 |
CVE-2024-7491 |
Wordfence | |
| 6.3 Medium | WPGSI: Spreadsheet Integration | Broken Access Control Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 3.8.0 |
CVE-2024-6590 |
Wordfence | |
| 6.1 Medium | XT Ajax Add To Cart for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.1.2 |
CVE-2024-8716 |
Wordfence | |
| 6.5 Medium | Product Carousel Slider & Grid Ultimate for WooCommerce | Local File Inclusion Authenticated Local File Inclusion |
≤ 1.9.10 Fixed in 1.10.0 |
CVE-2024-44048 |
Patchstack | |
| 6.1 Medium | Waitlist Woocommerce ( Back in stock notifier ) | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.7.5 |
CVE-2024-8724 |
Wordfence | |
| 5.3 Medium | WooCommerce Multiple Free Gift | Broken Access Control Insufficient Server-Side Validation to Arbitrary Gift Adding No login needed |
≤ 1.2.3 |
CVE-2022-3459 |
Wordfence | |
| 6.4 Medium | Betheme | Responsive Multipurpose WordPress & WooCommerce | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File |
≤ 27.5.5 |
CVE-2024-5567 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget |
≤ 6.0.3 |
CVE-2024-8440 |
Wordfence | |
| 6.4 Medium | Betheme | Responsive Multipurpose WordPress & WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 27.5.6 |
CVE-2024-3998 |
Wordfence | |
| 5.9 Medium | Web and WooCommerce Addons for WPBakery Builder | Cross-Site Scripting |
≤ 1.4.6 |
CVE-2024-43960 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.