WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High YITH WooCommerce Waitlist Premium Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user ≤ 3.35.0 CVE-2026-14359 Wordfence
8.6 High ELEX WooCommerce Request a Quote Plugin elex-request-a-quote SQL Injection Unauthenticated SQLi via variation_id No login needed < 2.4.1 Fixed in 2.4.1 CVE-2026-14962 WPScan
8.1 High Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration Authentication Bypass Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint No login needed ≤ 3.9.8 CVE-2026-76009 Wordfence
7.5 High WooCommerce Plugin woocommerce Denial of Service Denial of Service Attack No login needed < 11.1.0 Fixed in 11.1.0 CVE-2026-48888 Patchstack
7.5 High Csomagpontok és szállítási címkék WooCommerce-hez Plugin hungarian-pickup-points-for-woocommerce Broken Access Control No login needed < 4.2.8 Fixed in 4.2.8 CVE-2026-81790 Patchstack
8.8 High Abandoned Cart Pro for WooCommerce Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 10.7.1 CVE-2026-81543 Wordfence
7.6 High WooCommerce Plugin woocommerce SQL Injection < 11.0 Fixed in 11.0 CVE-2026-57777 Patchstack
7.5 High WooCommerce Product Attachment Plugin woo-product-attachment Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.3 CVE-2026-81774 Patchstack
7.1 High Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Cross-Site Scripting No login needed ≤ 3.1.5 Fixed in 3.1.6 CVE-2026-81288 Patchstack
8.8 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored XSS via 'comment' Parameter No login needed < 5.118.0 Fixed in 5.118.0 CVE-2026-76585 WPScan
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form No login needed ≤ 5.106.0 CVE-2026-6176 Wordfence
8.5 High Suggestion Engine for WooCommerce Plugin woo-suggestion-engine SQL Injection ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-81277 Patchstack
7.1 High Music Player for WooCommerce Plugin music-player-for-woocommerce Cross-Site Scripting No login needed ≤ 1.8.9 Fixed in 1.9.0 CVE-2026-78283 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78257 Patchstack
8.6 High Mobile App for WooCommerce Plugin mobile-app-for-woocommerce Broken Access Control No login needed ≤ 0.4.62 Fixed in 0.4.63 CVE-2026-27330 Patchstack
7.5 High StoreGrowth: Smart Sales Booster for WooCommerce Plugin Price Manipulation Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart No login needed < 2.1.2 Fixed in 2.1.2 CVE-2026-78137 WPScan
7.5 High WooCommerce Lottery Plugin woocommerce-lottery SQL Injection Unauthenticated Time-Based SQL Injection via 'orderby' and 'order' Parameters No login needed ≤ 2.2.9 CVE-2026-18884 Wordfence
8.7 High Order Tip for WooCommerce Plugin order-tip-woo Arbitrary File Deletion Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajax < 1.6.0 Fixed in 1.6.0 CVE-2026-77693 WPScan
7.2 High ShopEngine Elementor WooCommerce Builder Addon Plugin shopengine Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes ≤ 4.9.4 CVE-2026-75971 Wordfence
8.6 High ShopBuilder Pro – Elementor WooCommerce Builder Addons Plugin shopbuilder-pro Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed ≤ 2.2.0 CVE-2026-32477 Patchstack
8.6 High WooCommerce File Approval Plugin woocommerce-file-approval Arbitrary File Deletion No login needed ≤ 10.7 CVE-2026-28171 Patchstack
7.5 High Advanced Product Fields (Product Addons) for WooCommerce Plugin advanced-product-fields-for-woocommerce Other Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request No login needed ≤ 1.6.21 CVE-2026-2996 Wordfence
7.1 High Paymob for WooCommerce Plugin paymob-for-woocommerce Cross-Site Scripting No login needed ≤ 4.1.10 Fixed in 4.1.11 CVE-2026-66611 Patchstack
7.1 High Swatchly – WooCommerce Variation Swatches for Products Plugin swatchly Cross-Site Scripting WooCommerce Variation Swatches for Products plugin <= 1.4.13 - Cross Site Scripting (XSS) No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2026-66605 Patchstack
8.5 High YITH WooCommerce Membership Premium Plugin yith-woocommerce-membership-premium SQL Injection ≤ 2.33.0 Fixed in 2.33.1 CVE-2026-32552 Patchstack
7.1 High MWB HubSpot for WooCommerce Plugin makewebbetter-hubspot-for-woocommerce Authentication Bypass Broken Authentication ≤ 1.6.7 CVE-2026-73396 Patchstack
7.1 High License Manager for WooCommerce Plugin license-manager-for-woocommerce SQL Injection ≤ 3.0.18 Fixed in 3.0.19 CVE-2026-73345 Patchstack
7.5 High Extra Product Options & Add-Ons for WooCommerce Plugin woocommerce-tm-extra-product-options Path Traversal Arbitrary File Download No login needed < 7.6 Fixed in 7.6 CVE-2026-73181 Patchstack
7.5 High Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Information Disclosure Unauthenticated Customer File Disclosure via getpublicfileupload No login needed < 1.2.176 Fixed in 1.2.176 CVE-2026-19728 WPScan
7.2 High WCPOS Plugin woocommerce-pos Remote Code Execution Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine ≤ 1.9.14 CVE-2026-17581 Wordfence
7.2 High Autopay Plugin platnosci-online-blue-media Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_editor_content' Parameter No login needed ≤ 5.0.0 CVE-2026-15002 Wordfence
7.5 High Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Information Disclosure Unauthenticated Feed Configuration Disclosure No login needed < 13.5.7 Fixed in 13.5.7 CVE-2026-16611 WPScan
8.6 High Paymob for WooCommerce Plugin paymob-for-woocommerce SQL Injection Unauthenticated SQL Injection via Paymob Callback Pixel Lookup No login needed < 4.1.9 Fixed in 4.1.9 CVE-2026-15205 WPScan
7.1 High Samex - Clean, Minimal Shop WooCommerce Theme samex Cross-Site Scripting WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) No login needed ≤ 2.5, ≤ 1.7 CVE-2026-28154 Patchstack
7.6 High MailChimp For WooCommerce Plugin mailchimp-for-woocommerce SQL Injection < 6.2 Fixed in 6.2 CVE-2026-73346 Patchstack
7.1 High Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin colissimo-shipping-methods-for-woocommerce Cross-Site Scripting No login needed ≤ 2.10.0 Fixed in 3.0.0 CVE-2026-66697 Patchstack
7.1 High MultiParcels Shipping For WooCommerce Plugin multiparcels-shipping-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.30.36 CVE-2026-66655 Patchstack
7.1 High Local Delivery Drivers for WooCommerce Plugin local-delivery-drivers-for-woocommerce Cross-Site Scripting No login needed ≤ 3.0.0 CVE-2026-66468 Patchstack
7.5 High StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control No login needed ≤ 2.1.1 CVE-2026-66466 Patchstack
7.5 High WooCommerce Appointments Plugin woocommerce-appointments Information Disclosure Sensitive Data Exposure No login needed ≤ 5.3.8 CVE-2026-66462 Patchstack
7.5 High SMEPay: UPI Gateway for WooCommerce Plugin smepay-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 1.0.5 CVE-2026-66461 Patchstack
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 5.0.10 Fixed in 5.0.11 CVE-2026-66441 Patchstack
7.5 High Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) Plugin clink-gateway-for-woocommerce Broken Access Control No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2026-66431 Patchstack
7.5 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control No login needed ≤ 2.0.3 Fixed in 2.0.5 CVE-2026-27345 Patchstack
8.8 High Autopay / Blue Media for WooCommerce Plugin Cross-Site Scripting Unauthenticated Stored XSS via CSS Editor No login needed < 5.0.1 Fixed in 5.0.1 CVE-2026-14293 WPScan
7.5 High WPC Order Tip for WooCommerce Plugin wpc-order-tip Information Disclosure Unauthenticated Order Data Disclosure No login needed < 3.3.1 Fixed in 3.3.1 CVE-2026-18357 WPScan
8.8 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Remote Code Execution Shop Manager+ Arbitrary Plugin Installation < 2.0.1 Fixed in 2.0.1 CVE-2026-15215 WPScan
7.5 High WPC Name Your Price for WooCommerce Plugin wpc-name-your-price Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-16620 WPScan
7.5 High CoCart Plugin cart-rest-api-for-woocommerce Price Manipulation Unauthenticated Arbitrary Price Manipulation No login needed < 4.9.0 Fixed in 4.9.0 CVE-2026-10524 WPScan
7.5 High Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Price Manipulation Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order No login needed < 2.0.20 Fixed in 2.0.20 CVE-2026-13399 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only