WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 951–1,000 of 2,122 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Primer MyData for Woocommerce | Cross-Site Request Forgery No login needed |
≤ 4.2.5 Fixed in 4.2.6 |
CVE-2025-53575 |
Patchstack | |
| 7.2 High | Kadence WooCommerce Email Designer | Privilege Escalation |
≤ 1.5.16 Fixed in 1.5.17 |
CVE-2025-54697 |
Patchstack | |
| 7.5 High | Membership For WooCommerce | Broken Access Control No login needed |
≤ 2.9.0 Fixed in 3.0.0 |
CVE-2025-54692 |
Patchstack | |
| 4.3 Medium | YITH WooCommerce Popup | Cross-Site Request Forgery No login needed |
≤ 1.48.0 Fixed in 1.48.1 |
CVE-2025-54675 |
Patchstack | |
| 5.4 Medium | Product Configurator for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 1.4.4 Fixed in 1.5.0 |
CVE-2025-54674 |
Patchstack | |
| 7.1 High | WooCommerce Shop Page Builder | Cross-Site Scripting No login needed |
≤ 2.27.7 |
CVE-2025-28999 |
Patchstack | |
| 6.5 Medium | Thank You Page Customizer for WooCommerce | Broken Access Control Increase Your Sales <= 1.1.7 - Broken Access Control |
≤ 1.1.7 Fixed in 1.1.8 |
CVE-2025-30993 |
Patchstack | |
| 6.5 Medium | WooCommerce Fortnox Integration | Cross-Site Scripting |
≤ 4.5.6 Fixed in 4.5.7 |
CVE-2025-47610 |
Patchstack | |
| 9.9 Critical | Product XML Feed Manager for WooCommerce | Remote Code Execution |
≤ 2.9.3 Fixed in 2.9.4 |
CVE-2025-49887 |
Patchstack | |
| 8.5 High | WooCommerce Point Of Sale (POS) | SQL Injection |
≤ 1.4 |
CVE-2025-52820 |
Patchstack | |
| 5.3 Medium | FiboSearch | Broken Access Control No login needed |
≤ 1.32.1 Fixed in 1.32.2 |
CVE-2025-47444 |
Patchstack | |
| 8.1 High | WooCommerce Purchase Orders | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
≤ 1.0.2 |
CVE-2025-5391 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.3.10 |
CVE-2025-7646 |
Wordfence | |
| 6.4 Medium | Customer Reviews for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via `author` Parameter |
≤ 5.80.2 |
CVE-2025-5720 |
Wordfence | |
| 4.3 Medium | Bonanza – WooCommerce Free Gifts Lite | Broken Access Control WooCommerce Free Gifts Lite <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Opt In Success |
≤ 1.0.0 |
CVE-2025-6730 |
Wordfence | |
| 5.3 Medium | WoodMart - Multipurpose WooCommerce | Broken Access Control Multipurpose WooCommerce Theme <= 8.2.6 - Improper Input Validation Leading to Unauthenticated Cart Manipulation No login needed |
≤ 8.2.6 |
CVE-2025-8097 |
Wordfence | |
| 6.5 Medium | B1.lt for WooCommerce | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 2.2.56 |
CVE-2025-6717 |
Wordfence | |
| 6.4 Medium | Crowdfunding for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter |
≤ 3.1.14 |
CVE-2025-5767 |
Wordfence | |
| 8.8 High | B1.lt for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Injection |
≤ 2.2.57 |
CVE-2025-6718 |
Wordfence | |
| 9.8 Critical | WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet | Arbitrary File Upload Warranty Management, Refund Policy, Manage User Wallet <= 3.2.6 - Unauthenticated Arbitrary File Upload No login needed |
≤ 3.2.6 |
CVE-2025-6222 |
Wordfence | |
| 4.3 Medium | Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship | Broken Access Control Biteship <= 3.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) View Order Tracking Details |
≤ 3.2.0 |
CVE-2025-5816 |
Wordfence | |
| 7.5 High | Easy Video Player Wordpress & WooCommerce | Path Traversal Arbitrary File Download No login needed |
≤ 10.0 |
CVE-2025-28955 |
Patchstack | |
| 10.0 Critical | Medical Prescription Attachment Plugin for WooCommerce | Arbitrary File Upload No login needed |
≤ 1.2.3 |
CVE-2025-29009 |
Patchstack | |
| 6.5 Medium | Product XML Feed Manager for WooCommerce | Broken Access Control No login needed |
≤ 2.9.2 Fixed in 2.9.3 |
CVE-2025-30959 |
Patchstack | |
| 8.5 High | ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes | SQL Injection Subscriber+ SQL Injection |
≤ 1.4.9 Fixed in 1.5.0 |
CVE-2025-47645 |
Patchstack | |
| 6.5 Medium | Wishlist for WooCommerce | Broken Access Control No login needed |
≤ 3.2.3 Fixed in 3.2.4 |
CVE-2025-49319 |
Patchstack | |
| 7.1 High | PW WooCommerce On Sale! | Broken Access Control |
≤ 1.39 Fixed in 1.40 |
CVE-2025-49888 |
Patchstack | |
| 4.3 Medium | Wallet System for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 2.6.7 Fixed in 2.6.8 |
CVE-2025-54041 |
Patchstack | |
| 4.3 Medium | WooCommerce Google Sheet Connector | Cross-Site Request Forgery No login needed |
≤ 1.3.20 Fixed in 1.4.0 |
CVE-2025-54030 |
Patchstack | |
| 8.2 High | Counter live visitors for WooCommerce | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion in wcvisitor_get_block No login needed |
≤ 1.3.6 |
CVE-2025-7359 |
Wordfence | |
| 6.4 Medium | WPC Smart Compare for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.4.6 |
CVE-2025-5530 |
Wordfence | |
| 4.3 Medium | Order Delivery Date Pro for WooCommerce | Information Disclosure Unauthenticated Arbitrary Post Title Disclosure No login needed |
2.0 – < 12.6.0 Fixed in 12.6.0 |
CVE-2025-2942 |
WPScan | |
| 6.5 Medium | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification No login needed |
≤ 6.7.16 |
CVE-2025-3780 |
Wordfence | |
| 8.5 High | Printcart Web to Print Product Designer for WooCommerce | SQL Injection |
≤ 2.4.0 Fixed in 2.4.1 |
CVE-2025-24780 |
Patchstack | |
| 6.5 Medium | Paytiko for WooCommerce | Broken Access Control |
≤ 1.3.21 |
CVE-2025-50032 |
Patchstack | |
| 9.8 Critical | WooCommerce Product Multi-Action | PHP Object Injection Deserialization of untrusted data No login needed |
≤ 1.3 |
CVE-2025-49417 |
Patchstack | |
| 4.3 Medium | WooCommerce Shop Page Builder | Broken Access Control |
≤ 2.27.7 |
CVE-2025-29001 |
Patchstack | |
| 4.3 Medium | Trust Payments Gateway for WooCommerce (JavaScript Library) | Cross-Site Request Forgery No login needed |
≤ 1.3.6 Fixed in 1.3.7 |
CVE-2025-53569 |
Patchstack | |
| 6.4 Medium | PayMaster for WooCommerce | Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 0.4.31 |
CVE-2025-6729 |
Wordfence | |
| 6.5 Medium | Mollie Payments for WooCommerce | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 8.0.2 Fixed in 8.0.3 |
CVE-2025-39362 |
Patchstack | |
| 7.2 High | Amazon Products to WooCommerce | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed |
≤ 1.2.7 |
CVE-2025-5817 |
Wordfence | |
| 9.8 Critical | Drag and Drop Multiple File Upload (Pro) - WooCommerce | Arbitrary File Upload WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File Upload No login needed |
≤ 1.7.1, 5.0 – 5.0.5 |
CVE-2025-5746 |
Wordfence | |
| 7.5 High | WPB Category Slider for WooCommerce | Local File Inclusion |
≤ 1.71 |
CVE-2025-53281 |
Patchstack | |
| 7.1 High | Additional Order Filters for WooCommerce | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.22 Fixed in 1.23 |
CVE-2025-53271 |
Patchstack | |
| 4.3 Medium | WooCommerce PDF Invoice Builder | Cross-Site Request Forgery No login needed |
≤ 1.2.148 Fixed in 1.2.149 |
CVE-2025-53203 |
Patchstack | |
| 7.1 High | WPCRM - CRM for Contact form CF7 & WooCommerce | Cross-Site Scripting CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.0 |
CVE-2025-24774 |
Patchstack | |
| 8.1 High | MBStore - Digital WooCommerce | Local File Inclusion Digital WooCommerce WordPress Theme <= 2.3 - Local File Inclusion No login needed |
≤ 2.3 |
CVE-2025-28947 |
Patchstack | |
| 7.1 High | Woocommerce Line Notify | Cross-Site Scripting No login needed |
≤ 1.1.7 |
CVE-2025-30972 |
Patchstack | |
| 10.0 Critical | Drag and Drop Multiple File Upload (Pro) - WooCommerce | Arbitrary File Upload WooCommerce plugin <= 5.0.6 - Arbitrary File Upload No login needed |
≤ 5.0.6 Fixed in 5.0.7 |
CVE-2025-49885 |
Patchstack | |
| 8.1 High | Samex - Clean, Minimal Shop WooCommerce | Local File Inclusion Clean, Minimal Shop WooCommerce WordPress Theme <= 2.6 - Local File Inclusion No login needed |
≤ 2.6 |
CVE-2023-25998 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.