WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Mailchimp for WooCommerce Plugin mailchimp-for-woocommerce Broken Access Control Unauthenticated Broken Access Control in REST API No login needed < 6.1.1 Fixed in 6.1.1 CVE-2026-92435 WPScan
5.3 Medium Rede Itaú for WooCommerce Plugin Broken Access Control Unauthenticated Order Status Manipulation via PIX Webhook No login needed 3.6.1 – < 5.4.7 Fixed in 5.4.7 CVE-2026-92430 WPScan
4.9 Medium Store Exporter Plugin woocommerce-exporter Path Traversal Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read and Arbitrary File Deletion via 'filename' Parameter ≤ 2.8.0 CVE-2026-16777 Wordfence
5.3 Medium WP Ghost (Hide My WP Ghost) Plugin Other Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters No login needed 7.0.10 – < 7.0.11 Fixed in 7.0.11 CVE-2026-86796 WPScan
4.9 Medium Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Contributor+ Payment Gateway Credential Disclosure 5.3.6 – < 5.6.0 Fixed in 5.6.0 CVE-2026-91019 WPScan
4.3 Medium Active Products Tables for WooCommerce Plugin Cross-Site Request Forgery Subscriber+ Arbitrary Post Title Modification via woot_update_attachment 2.1.2 – < 2.1.3 Fixed in 2.1.3 CVE-2026-91009 WPScan
4.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Cross-Site Request Forgery Subscription Cancellation via CSRF No login needed < 2.0.3 Fixed in 2.0.3 CVE-2026-87860 WPScan
5.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Information Disclosure Unauthenticated Subscription Data Disclosure via REST API Secret Key Bypass No login needed < 2.0.3 Fixed in 2.0.3 CVE-2026-87854 WPScan
5.3 Medium Ni WooCommerce Sales Report Plugin ni-woocommerce-sales-report Information Disclosure Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter No login needed < 4.2.0 Fixed in 4.2.0 CVE-2026-78474 WPScan
6.4 Medium ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets Plugin shopengine Cross-Site Scripting All in One WooCommerce Solution with eCommerce Templates & Woo Widgets <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter ≤ 4.9.5 CVE-2026-85575 Wordfence
4.9 Medium Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Broken Access Control Contributor+ Arbitrary Product Deletion via Shortcode < 3.1.1 Fixed in 3.1.1 CVE-2026-87919 WPScan
4.3 Medium BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-84024 WPScan
6.5 Medium BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-84023 WPScan
5.3 Medium Flexible Quantity – Measurement Price Calculator for WooCommerce Plugin flexible-quantity-measurement-price-calculator-for-woocommerce Broken Access Control Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control No login needed ≤ 2.3.21 Fixed in 2.3.22 CVE-2026-62136 Patchstack
5.3 Medium Deposits and Partial Payments for WooCommerce Plugin advanced-partial-payment-or-deposit-for-woocommerce Broken Access Control No login needed ≤ 3.1.0 Fixed in 4.0.1 CVE-2026-27378 Patchstack
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title No login needed < 4.18.1 Fixed in 4.18.1 CVE-2026-82305 WPScan
4.3 Medium Advanced Customized Prompts Plugin Broken Access Control Subscriber+ WooCommerce Order Item Metadata Tampering ≤ 1.0.1 CVE-2026-14566 WPScan
6.1 Medium Themify – WooCommerce Product Filter Plugin themify-wc-product-filter Cross-Site Scripting WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting No login needed ≤ 1.5.5 CVE-2026-78172 Wordfence
6.1 Medium HUSKY Plugin woocommerce-products-filter Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.3 CVE-2026-18562 Wordfence
5.3 Medium OTP Login & Register Woocommerce Plugin mobile-login-woocommerce Authentication Bypass Unauthenticated Authentication Bypass via Brute Force No login needed ≤ 2.7.2 CVE-2026-12215 Wordfence
6.5 Medium Robokassa payment gateway for Woocommerce Plugin robokassa Broken Access Control No login needed ≤ 1.8.9 CVE-2026-78536 Patchstack
6.5 Medium WPMR Google Feed Manager for WooCommerce Plugin wp-product-feed-manager SQL Injection Authenticated (Administrator+) SQL Injection via 'feed' Parameter ≤ 2.23.7 CVE-2026-19778 Wordfence
4.3 Medium Checkout Custom Fields Builder for WooCommerce Plugin checkout-custom-fields-builder-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation via 'plugin' Parameter ≤ 1.1.5 CVE-2026-19802 Wordfence
5.9 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Broken Access Control Subscriber+ Stored Payment Method Assignment via IDOR 1.1.0 – < 2.0.26 Fixed in 2.0.26 CVE-2026-80341 WPScan
5.3 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Information Disclosure Unauthenticated Customer PII Disclosure via order-pay No login needed 1.0.0 – < 2.0.26 Fixed in 2.0.26 CVE-2026-80340 WPScan
5.3 Medium Payment Plugins for Stripe WooCommerce Plugin woo-stripe-payment Information Disclosure Unauthenticated Customer PII Disclosure via order-pay No login needed 4.0.0 – < 4.0.12 Fixed in 4.0.12 CVE-2026-80339 WPScan
6.5 Medium Ultimate Gift Cards for WooCommerce Plugin woo-gift-cards-lite Broken Access Control Subscriber+ Gift Card Theft and Destruction via Unauthorized Redemption < 3.2.10 Fixed in 3.2.10 CVE-2026-75861 WPScan
4.3 Medium ilGhera Reviso Exporter for WooCommerce Plugin wc-exporter-for-reviso Broken Access Control Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function ≤ 1.2.3 CVE-2026-8615 Wordfence
6.1 Medium Product Filter for WooCommerce by WBW Plugin woo-product-filter Cross-Site Scripting Reflected Cross-Site Scripting via 'wpf_fid' Parameter No login needed ≤ 3.4.2 CVE-2026-7804 Wordfence
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Privilege Escalation No login needed ≤ 6.1.5 CVE-2026-81792 Patchstack
5.3 Medium E-cab Taxi Booking Manager for Woocommerce Plugin ecab-taxi-booking-manager Price Manipulation Unauthenticated Price Manipulation via mptbm_add_to_cart No login needed 2.0.1 – < 2.0.5 Fixed in 2.0.5 CVE-2026-84045 WPScan
5.3 Medium ePayco Payment Gateway for WooCommerce Plugin Other Unauthenticated Payment Confirmation Bypass No login needed < 8.4.7 Fixed in 8.4.7 CVE-2026-84043 WPScan
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.60 Fixed in 2.1.70 CVE-2026-85311 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2026-85303 Patchstack
6.5 Medium Product Variations Swatches for WooCommerce Plugin product-variations-swatches-for-woocommerce Cross-Site Scripting ≤ 1.1.18 Fixed in 1.1.19 CVE-2026-81282 Patchstack
6.5 Medium Pre-Orders for WooCommerce Plugin pre-orders-for-woocommerce Authentication Bypass Bypass Vulnerability No login needed ≤ 2.3 CVE-2026-84849 Patchstack
5.3 Medium Ultimate Gift Cards For WooCommerce Plugin woo-gift-cards-lite Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2026-84760 Patchstack
4.3 Medium CatalogX Plugin woocommerce-catalog-enquiry Content Injection Unauthenticated Email Content Injection via Shared Transient No login needed < 6.1.3 Fixed in 6.1.3 CVE-2026-79621 WPScan
5.3 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint No login needed 5.0.13 – < 5.0.15 Fixed in 5.0.15 CVE-2026-74927 WPScan
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-81762 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Information Disclosure Sensitive Data Exposure ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-81280 Patchstack
4.3 Medium Notifima Plugin woocommerce-product-stock-alert Broken Access Control Subscriber+ Stock Alert Unsubscription via IDOR < 3.1.4 Fixed in 3.1.4 CVE-2026-78139 WPScan
4.3 Medium Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Information Disclosure Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html < 2.21.0 Fixed in 2.21.0 CVE-2026-78138 WPScan
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78258 Patchstack
4.3 Medium WooCommerce Bookings Plugin Broken Access Control Subscriber+ Draft Bookable Product Creation via Missing Authorization < 3.9.0 Fixed in 3.9.0 CVE-2026-14853 WPScan
6.5 Medium WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Path Traversal Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter ≤ 4.9.8 CVE-2026-18027 Wordfence
5.3 Medium FiboSearch Plugin ajax-search-for-woocommerce Information Disclosure Unauthenticated Password-Protected Product Information Disclosure No login needed < 1.34.1 Fixed in 1.34.1 CVE-2026-16612 WPScan
4.2 Medium LitExtension: Store to WooCommerce Migration Plugin Cross-Site Request Forgery Connector Token Takeover via CSRF No login needed ≤ 1.2.5 CVE-2026-15046 WPScan
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control < 2.0.8 Fixed in 2.0.8 CVE-2026-73363 Patchstack
5.3 Medium Membership For WooCommerce Plugin membership-for-woocommerce Information Disclosure Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass No login needed < 3.1.2 Fixed in 3.1.2 CVE-2026-19709 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only