WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 901–950 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 19 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Get Quote For Woocommerce – Request A Quote For Woocommerce Plugin get-a-quote-for-woocommerce Broken Access Control Request A Quote For Woocommerce <= 1.0.0 - Missing Authorization to Unauthenticated Quote PDF and CSV Download No login needed ≤ 1.0.0 CVE-2024-9430 Wordfence
6.4 Medium Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Plugin gift-voucher Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.4.4 CVE-2024-9165 Wordfence
5.3 Medium WooCommerce PDF Invoices & Packing Slips Plugin woocommerce-pdf-invoices-packing-slips Broken Access Control No login needed ≤ 3.8.6 Fixed in 3.8.7 CVE-2024-50421 Patchstack
6.4 Medium SMSAlert - WooCommerce Plugin sms-alert Cross-Site Scripting WooCommerce <= 3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_subscribe Shortcode ≤ 3.7.5 CVE-2024-10233 Wordfence
4.3 Medium WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Broken Access Control Missing Authorization to Authenticated (Subscriber+) Message Activation/Deactivation ≤ 4.2.1 CVE-2024-10437 Wordfence
6.5 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.19 Fixed in 1.4.20 CVE-2024-50447 Patchstack
6.1 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.2.133 CVE-2024-9214 Wordfence
6.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Request Forgery The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates No login needed ≤ 4.2.4 CVE-2024-9943 Wordfence
4.3 Medium HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce Plugin hurrytimer Broken Access Control An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce <= 2.10.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Publication ≤ 2.10.0 CVE-2024-8667 Wordfence
4.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending ≤ 4.2.4 CVE-2024-9531 Wordfence
5.4 Medium CartBounty – Save and recover abandoned carts for WooCommerce Plugin woo-save-abandoned-carts Cross-Site Request Forgery No login needed ≤ 8.2 Fixed in 8.2.1 CVE-2024-47634 Patchstack
6.1 Medium Edit WooCommerce Templates Plugin woo-edit-templates Cross-Site Scripting Reflected Cross-Site Scripting via page No login needed ≤ 1.1.2 CVE-2024-10049 Wordfence
5.9 Medium Email Template Customizer for WooCommerce Plugin email-template-customizer-for-woo Cross-Site Scripting ≤ 1.2.9.1 Fixed in 1.2.9.2 CVE-2024-49288 Patchstack
4.3 Medium Linked Variation for WooCommerce Plugin linked-variation-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 2.0.0 CVE-2024-48047 Patchstack
6.1 Medium Persian WooCommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.0.2 CVE-2024-9213 Wordfence
5.3 Medium WooCommerce Smart Coupons Plugin Broken Access Control Unauthenticated Coupon Creation No login needed < 4.6.5 Fixed in 4.6.5 CVE-2020-36841 Wordfence
6.3 Medium Discount Rules for WooCommerce Plugin woo-discount-rules Broken Access Control Missing Authorization ≤ 2.0.2 CVE-2020-36834 Wordfence
4.7 Medium Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons Plugin woo-discount-rules Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed ≤ 2.6.5 CVE-2024-8541 Wordfence
5.3 Medium WooCommerce Plugin woocommerce Content Injection Unauthenticated HTML Injection No login needed ≤ 9.0.2 CVE-2024-9944 Wordfence
4.3 Medium Order Attachments for WooCommerce Plugin order-attachments-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary File Upload 2.0 – 2.4.1 CVE-2024-9756 Wordfence
4.3 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template ≤ 5.6.11 CVE-2024-8913 Wordfence
6.5 Medium WordPress Comments Import & Export Plugin comments-import-export-woocommerce Path Traversal Authenticated (Author+) Arbitrary File Read via Directory Traversal ≤ 2.3.7 CVE-2024-7514 Wordfence
5.9 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist SQL Injection Unauthenticated SQL Injection via lang parameters No login needed ≤ 2.8.2 CVE-2024-9156 WPScan
6.1 Medium Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.15 CVE-2024-9377 Wordfence
6.1 Medium Maximum Products per User for WooCommerce Plugin maximum-products-per-user-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.2.8 CVE-2024-9205 Wordfence
6.1 Medium WooCommerce Multilingual & Multicurrency with WPML Plugin woocommerce-multilingual Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.3.7 CVE-2024-8629 Wordfence
5.9 Medium Themify – WooCommerce Product Filter Plugin themify-wc-product-filter Cross-Site Scripting ≤ 1.5.1 Fixed in 1.5.2 CVE-2024-44046 Patchstack
6.6 Medium Cities Shipping Zones for WooCommerce Plugin cities-shipping-zones-for-woocommerce Local File Inclusion ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-47309 Patchstack
4.7 Medium Checkout Field Editor (Checkout Manager) for WooCommerce Plugin woo-checkout-field-editor-pro Cross-Site Scripting Reflected Cross-Site Scripting via render_review_request_notice No login needed ≤ 2.0.3 CVE-2024-8499 Wordfence
6.1 Medium Quantity Dynamic Pricing & Bulk Discounts for WooCommerce Plugin wholesale-pricing-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.8.0 CVE-2024-9384 Wordfence
6.1 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Cross-Site Scripting Lite <= 2.7.3 - Reflected Cross-Site Scripting No login needed ≤ 2.7.3 CVE-2024-9345 Wordfence
5.4 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Arbitrary Shortcode Execution Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 5.7.34 CVE-2024-8254 Wordfence
6.1 Medium Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More Plugin woocommerce-exporter Cross-Site Scripting Export Products, Export Orders, Export Subscriptions, and More <= 2.7.2.1 - Reflected Cross-Site Scripting No login needed ≤ 2.7.2.1 CVE-2024-8793 Wordfence
5.3 Medium EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Broken Access Control Missing Authorization No login needed ≤ 2.12.12 CVE-2024-9189 Wordfence
6.1 Medium EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.12.12 CVE-2024-8788 Wordfence
4.3 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 5.7.34 CVE-2024-8771 Wordfence
6.1 Medium Store Hours for WooCommerce Plugin order-hours-scheduler-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.3.20 CVE-2024-8872 Wordfence
5.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Update No login needed ≤ 4.17.3 CVE-2024-8678 Wordfence
5.3 Medium Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Plugin mycred Broken Access Control Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade No login needed ≤ 2.7.3 CVE-2024-8658 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.9.7 CVE-2024-8668 Wordfence
5.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin Broken Access Control Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe No login needed ≤ 1.3.6.1 CVE-2024-7491 Wordfence
6.3 Medium WPGSI: Spreadsheet Integration Plugin wpgsi Broken Access Control Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 3.8.0 CVE-2024-6590 Wordfence
6.1 Medium XT Ajax Add To Cart for WooCommerce Plugin xt-woo-ajax-add-to-cart Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.2 CVE-2024-8716 Wordfence
6.5 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated Local File Inclusion ≤ 1.9.10 Fixed in 1.10.0 CVE-2024-44048 Patchstack
6.1 Medium Waitlist Woocommerce ( Back in stock notifier ) Plugin waitlist-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.7.5 CVE-2024-8724 Wordfence
5.3 Medium WooCommerce Multiple Free Gift Plugin woocommerce-multiple-free-gift Broken Access Control Insufficient Server-Side Validation to Arbitrary Gift Adding No login needed ≤ 1.2.3 CVE-2022-3459 Wordfence
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File ≤ 27.5.5 CVE-2024-5567 Wordfence
6.4 Medium Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget ≤ 6.0.3 CVE-2024-8440 Wordfence
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 27.5.6 CVE-2024-3998 Wordfence
5.9 Medium Web and WooCommerce Addons for WPBakery Builder Plugin vc-addons-by-bit14 Cross-Site Scripting ≤ 1.4.6 CVE-2024-43960 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only