WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–74 of 74 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Shiprocket Plugin shiprocket Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.8 CVE-2025-68051 Patchstack
7.1 High bidorbuy Store Integrator Plugin bidorbuystoreintegrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.12.0 CVE-2025-68883 Patchstack
8.1 High Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Plugin dokan-lite Broken Access Control Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure ≤ 4.2.4 CVE-2025-14977 Wordfence
8.6 High Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-68044 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-67909 Patchstack
8.1 High Dør Plugin dor Local File Inclusion No login needed ≤ 2.4 Fixed in 2.4.1 CVE-2025-39466 Patchstack
8.6 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.2.23 Fixed in 4.2.24 CVE-2025-49916 Patchstack
8.8 High Dokan Pro Plugin Privilege Escalation Authenticated (Vendor+) Privilege Escalation ≤ 4.0.5 CVE-2025-5931 Wordfence
7.5 High Maya Business Plugin paymaya-checkout-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-53208 Patchstack
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.22 Fixed in 4.2.23 CVE-2025-48261 Patchstack
7.6 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.5.6 Fixed in 2.5.7 CVE-2025-49263 Patchstack
7.5 High wp-dashboard-notes Plugin Broken Access Control Contributor+ Arbitrary Private Notes Update via IDOR No login needed < 1.0.11 Fixed in 1.0.11 CVE-2023-7239 WPScan
7.3 High Wolmart | Multi-Vendor Marketplace WooCommerce Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution in wolmart_loadmore No login needed ≤ 1.8.11 CVE-2024-13793 Wordfence
8.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.0.23 Fixed in 4.0.24 CVE-2023-51355 Patchstack
7.5 High Paid Memberships Pro Plugin paid-memberships-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2024-37277 Patchstack
7.1 High WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.11 Fixed in 3.6.12 CVE-2024-44009 Patchstack
7.5 High Stripe Payments For WooCommerce by Checkout Plugin checkout-plugins-stripe-woo Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2024-43315 Patchstack
7.1 High WC Marketplace Plugin dc-woocommerce-multi-vendor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.17 CVE-2024-43213 Patchstack
7.3 High WooCommerce - PDF Vouchers Plugin Authentication Bypass PDF Vouchers <= 4.9.3 - Authentication Bypass to Voucher Vendor No login needed ≤ 4.9.3 CVE-2024-7027 Wordfence
8.8 High WP ERP Plugin erp SQL Injection Authenticated (Accounting Manager+) SQL Injection via vendor_id ≤ 1.13.0 CVE-2024-6666 Wordfence
8.6 High WC Marketplace Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.0.25 Fixed in 4.0.26 CVE-2024-24703 Patchstack
7.1 High WC Marketplace Plugin dc-woocommerce-multi-vendor Broken Access Control ≤ 4.1.3 Fixed in 4.1.4 CVE-2024-31304 Patchstack
7.5 High Contact Form builder with drag & drop for WordPress – Kali Forms Plugin kali-forms Broken Access Control Kali Forms Plugin <= 2.3.36 is vulnerable to Insecure Direct Object References (IDOR) No login needed ≤ 2.3.36 Fixed in 2.3.37 CVE-2024-22305 Patchstack
7.5 High WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Broken Access Control WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.6.1 is vulnerable to Insecure Direct Object References (IDOR) No login needed ≤ 7.6.1 Fixed in 7.6.2 CVE-2023-51502 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only