WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 176 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Pix for WooCommerce Plugin payment-gateway-pix-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.5.0 CVE-2026-3891 Wordfence
9.1 Critical WooCommerce License Manager Plugin fs-license-manager Arbitrary File Upload ≤ 7.0.6 Fixed in 7.0.7 CVE-2026-28114 Patchstack
9.8 Critical Registration & Login with Mobile Phone Number for WooCommerce Plugin registration-login-with-mobile-phone-number Broken Access Control No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-69052 Patchstack
9.4 Critical Order Listener for WooCommerce Plugin woc-order-alert Broken Access Control No login needed ≤ 3.6.1 Fixed in 3.6.2 CVE-2025-68018 Patchstack
9.3 Critical MailerLite – WooCommerce integration Plugin woo-mailerlite SQL Injection WooCommerce integration plugin <= 3.1.2 - SQL Injection No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-67945 Patchstack
9.8 Critical Registration & Login with Mobile Phone Number for WooCommerce Plugin Authentication Bypass No login needed ≤ 1.3.1 CVE-2025-10484 Wordfence
9.8 Critical Integration Opvius AI for WooCommerce Plugin woosa-ai-for-woocommerce Arbitrary File Deletion Unauthenticated Arbitrary File Deletion/Read via Path Traversal No login needed ≤ 1.3.0 CVE-2025-14301 Wordfence
9.8 Critical Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Remote Code Execution Unauthenticated Remote Code Execution No login needed ≤ 5.8.0 CVE-2025-13773 Wordfence
9.8 Critical File Uploader for WooCommerce Plugin file-uploader-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload via add-image-data No login needed ≤ 1.0.3 CVE-2025-13329 Wordfence
9.3 Critical Advance Seat Reservation Management for WooCommerce Plugin scw-seat-reservation SQL Injection No login needed ≤ 3.1 CVE-2025-58951 Patchstack
9.8 Critical Selling Commander for WooCommerce Plugin selling-commander-connector Privilege Escalation No login needed ≤ 1.2.46 CVE-2025-60243 Patchstack
10.0 Critical Support Ticket System for WooCommerce (Premium) Plugin support-ticket-system-for-woocommerce Arbitrary File Upload No login needed ≤ 2.0.7 CVE-2025-60235 Patchstack
10.0 Critical Custom User Registration Fields for WooCommerce Plugin user-registration-plugin-for-woocommerce Arbitrary File Upload No login needed ≤ 2.1.2 CVE-2025-60207 Patchstack
9.1 Critical Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing Remote Code Execution Arbitrary Code Execution ≤ 4.5.9 Fixed in 4.5.10 CVE-2025-47588 Patchstack
9.8 Critical WooCommerce Designer Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.9.26 CVE-2025-6440 Wordfence
9.8 Critical WooCommerce Vehicle Parts Finder Plugin woo-vehicle-parts-finder PHP Object Injection No login needed ≤ 3.7 Fixed in 3.8 CVE-2025-49380 Patchstack
9.8 Critical PPOM – Product Addons & Custom Fields for WooCommerce Plugin woocommerce-product-addon Arbitrary File Upload Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated Arbitrary File Upload No login needed ≤ 33.0.15 CVE-2025-11391 Wordfence
9.8 Critical WooCommerce Designer Pro Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.9.26 CVE-2025-6439 Wordfence
9.8 Critical Appy Pie Connect for WooCommerce Plugin appy-pie-connect-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via reset_user_password No login needed ≤ 1.1.2 CVE-2025-9286 Wordfence
10.0 Critical WooCommerce Designer Pro Plugin wc-designer-pro Arbitrary File Upload No login needed ≤ 1.9.24 CVE-2025-60219 Patchstack
9.8 Critical MultiLoca - WooCommerce Multi Locations Inventory Management Plugin Broken Access Control WooCommerce Multi Locations Inventory Management <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Options Update via 'wcmlim_settings_ajax_handler' No login needed ≤ 4.2.8 CVE-2025-9054 Wordfence
9.8 Critical Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) Plugin Arbitrary File Upload Uni CPO (Premium) <= 4.9.55 - Unauthenticated Arbitrary File Upload via 'uni_cpo_upload_file' No login needed ≤ 4.9.55 CVE-2025-10412 Wordfence
9.3 Critical WooCommerce Ultimate Gift Card Plugin woocommerce-ultimate-gift-card SQL Injection No login needed ≤ 2.9.6 Fixed in 2.9.7 CVE-2025-47569 Patchstack
10.0 Critical StoreKeeper for WooCommerce Plugin storekeeper-for-woocommerce Arbitrary File Upload No login needed ≤ 14.4.4 Fixed in 14.4.5 CVE-2025-48148 Patchstack
9.9 Critical ReachShip WooCommerce Multi-Carrier & Conditional Shipping Plugin elex-reachship-multi-carrier-conditional-shipping Arbitrary File Upload ≤ 4.3.1 Fixed in 4.3.2 CVE-2025-53213 Patchstack
9.8 Critical Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-54713 Patchstack
9.8 Critical Taxi Booking Manager for Woocommerce | E-cab Plugin ecab-taxi-booking-manager Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 1.3.0 CVE-2025-8898 Wordfence
9.9 Critical Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Remote Code Execution ≤ 2.9.3 Fixed in 2.9.4 CVE-2025-49887 Patchstack
9.8 Critical WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet Theme Arbitrary File Upload Warranty Management, Refund Policy, Manage User Wallet <= 3.2.6 - Unauthenticated Arbitrary File Upload No login needed ≤ 3.2.6 CVE-2025-6222 Wordfence
10.0 Critical Medical Prescription Attachment Plugin for WooCommerce Plugin medical-prescription-attachment-plugin-for-woocommerce Arbitrary File Upload No login needed ≤ 1.2.3 CVE-2025-29009 Patchstack
9.8 Critical WooCommerce Product Multi-Action Plugin woo-product-multiaction PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.3 CVE-2025-49417 Patchstack
9.8 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin Arbitrary File Upload WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File Upload No login needed ≤ 1.7.1, 5.0 – 5.0.5 CVE-2025-5746 Wordfence
10.0 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin drag-and-drop-file-upload-wc-pro Arbitrary File Upload WooCommerce plugin <= 5.0.6 - Arbitrary File Upload No login needed ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-49885 Patchstack
9.3 Critical GG Bought Together for WooCommerce Plugin gg-bought-together SQL Injection No login needed ≤ 1.0.2 CVE-2025-23967 Patchstack
9.8 Critical Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit Plugin wp-marketing-automations Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Installation No login needed ≤ 3.5.3 CVE-2025-1562 Wordfence
9.3 Critical WPCRM - CRM for Contact form CF7 & WooCommerce Plugin wpcrm SQL Injection CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - SQL Injection No login needed ≤ 3.2.0 CVE-2025-24773 Patchstack
9.8 Critical Rapyd Payment Extension for WooCommerce Plugin rapyd-payments PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-30618 Patchstack
9.3 Critical TicketBAI Facturas para WooCommerce Plugin wp-ticketbai SQL Injection No login needed ≤ 3.19 Fixed in 3.21 CVE-2025-24767 Patchstack
9.3 Critical Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart SQL Injection No login needed ≤ 2.5 CVE-2025-47608 Patchstack
9.3 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light SQL Injection Light plugin <= 2.4.37 - SQL Injection No login needed ≤ 2.4.37 CVE-2025-48122 Patchstack
10.0 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Remote Code Execution Light plugin <= 2.4.37 - Remote Code Execution (RCE) No login needed ≤ 2.4.37 CVE-2025-48123 Patchstack
9.8 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Privilege Escalation Light plugin <= 2.4.37 - Privilege Escalation No login needed ≤ 2.4.37 CVE-2025-48129 Patchstack
9.8 Critical eMagicOne Store Manager for WooCommerce Plugin store-manager-connector Arbitrary File Upload Unauthenticated Arbitrary File Upload via set_image() No login needed ≤ 1.2.5 CVE-2025-5058 Wordfence
9.1 Critical eMagicOne Store Manager for WooCommerce Plugin store-manager-connector Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.2.5 CVE-2025-4603 Wordfence
9.3 Critical WhatsCart - Whatsapp Abandoned Cart Recovery, Order Notifications, Chat Box, OTP for WooCommerce Plugin whatscart-for-woocommerce SQL Injection No login needed ≤ 1.1.0 CVE-2025-31056 Patchstack
9.3 Critical Bus Ticket Booking with Seat Reservation for WooCommerce Plugin scw-bus-seat-reservation SQL Injection No login needed ≤ 1.7 CVE-2025-31397 Patchstack
9.8 Critical CoinPayments.net Payment Gateway for WooCommerce Plugin coinpayments-payment-gateway-for-woocommerce PHP Object Injection No login needed ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47532 Patchstack
10.0 Critical Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration Arbitrary File Upload No login needed ≤ 2.3.9 Fixed in 2.4.0 CVE-2025-47641 Patchstack
9.3 Critical Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration SQL Injection No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-47640 Patchstack
10.0 Critical StoreKeeper for WooCommerce Plugin storekeeper-for-woocommerce Arbitrary File Upload No login needed ≤ 14.4.4 Fixed in 14.4.5 CVE-2025-47687 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only