WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 951–1,000 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Request Forgery No login needed ≤ 4.2.5 Fixed in 4.2.6 CVE-2025-53575 Patchstack
7.2 High Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Privilege Escalation ≤ 1.5.16 Fixed in 1.5.17 CVE-2025-54697 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control No login needed ≤ 2.9.0 Fixed in 3.0.0 CVE-2025-54692 Patchstack
4.3 Medium YITH WooCommerce Popup Plugin yith-woocommerce-popup Cross-Site Request Forgery No login needed ≤ 1.48.0 Fixed in 1.48.1 CVE-2025-54675 Patchstack
5.4 Medium Product Configurator for WooCommerce Plugin product-configurator-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.4.4 Fixed in 1.5.0 CVE-2025-54674 Patchstack
7.1 High WooCommerce Shop Page Builder Plugin dzs-wootable Cross-Site Scripting No login needed ≤ 2.27.7 CVE-2025-28999 Patchstack
6.5 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control Increase Your Sales <= 1.1.7 - Broken Access Control ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30993 Patchstack
6.5 Medium WooCommerce Fortnox Integration Plugin woocommerce-fortnox-integration Cross-Site Scripting ≤ 4.5.6 Fixed in 4.5.7 CVE-2025-47610 Patchstack
9.9 Critical Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Remote Code Execution ≤ 2.9.3 Fixed in 2.9.4 CVE-2025-49887 Patchstack
8.5 High WooCommerce Point Of Sale (POS) Plugin woo-point-of-salepos SQL Injection ≤ 1.4 CVE-2025-52820 Patchstack
5.3 Medium FiboSearch Plugin ajax-search-for-woocommerce Broken Access Control No login needed ≤ 1.32.1 Fixed in 1.32.2 CVE-2025-47444 Patchstack
8.1 High WooCommerce Purchase Orders Plugin wc-purchase-orders Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 1.0.2 CVE-2025-5391 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.3.10 CVE-2025-7646 Wordfence
6.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via `author` Parameter ≤ 5.80.2 CVE-2025-5720 Wordfence
4.3 Medium Bonanza – WooCommerce Free Gifts Lite Plugin bonanza-woocommerce-free-gifts-lite Broken Access Control WooCommerce Free Gifts Lite <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Opt In Success ≤ 1.0.0 CVE-2025-6730 Wordfence
5.3 Medium WoodMart - Multipurpose WooCommerce Theme Broken Access Control Multipurpose WooCommerce Theme <= 8.2.6 - Improper Input Validation Leading to Unauthenticated Cart Manipulation No login needed ≤ 8.2.6 CVE-2025-8097 Wordfence
6.5 Medium B1.lt for WooCommerce Plugin b1-accounting SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 2.2.56 CVE-2025-6717 Wordfence
6.4 Medium Crowdfunding for WooCommerce Plugin crowdfunding-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter ≤ 3.1.14 CVE-2025-5767 Wordfence
8.8 High B1.lt for WooCommerce Plugin b1-accounting Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Injection ≤ 2.2.57 CVE-2025-6718 Wordfence
9.8 Critical WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet Theme Arbitrary File Upload Warranty Management, Refund Policy, Manage User Wallet <= 3.2.6 - Unauthenticated Arbitrary File Upload No login needed ≤ 3.2.6 CVE-2025-6222 Wordfence
4.3 Medium Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship Plugin biteship Broken Access Control Biteship <= 3.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) View Order Tracking Details ≤ 3.2.0 CVE-2025-5816 Wordfence
7.5 High Easy Video Player Wordpress & WooCommerce Plugin fwdevp Path Traversal Arbitrary File Download No login needed ≤ 10.0 CVE-2025-28955 Patchstack
10.0 Critical Medical Prescription Attachment Plugin for WooCommerce Plugin medical-prescription-attachment-plugin-for-woocommerce Arbitrary File Upload No login needed ≤ 1.2.3 CVE-2025-29009 Patchstack
6.5 Medium Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Broken Access Control No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30959 Patchstack
8.5 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection Subscriber+ SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-47645 Patchstack
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Broken Access Control No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-49319 Patchstack
7.1 High PW WooCommerce On Sale! Plugin pw-woocommerce-on-sale Broken Access Control ≤ 1.39 Fixed in 1.40 CVE-2025-49888 Patchstack
4.3 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-54041 Patchstack
4.3 Medium WooCommerce Google Sheet Connector Plugin wc-gsheetconnector Cross-Site Request Forgery No login needed ≤ 1.3.20 Fixed in 1.4.0 CVE-2025-54030 Patchstack
8.2 High Counter live visitors for WooCommerce Plugin counter-visitor-for-woocommerce Arbitrary File Deletion Unauthenticated Arbitrary File Deletion in wcvisitor_get_block No login needed ≤ 1.3.6 CVE-2025-7359 Wordfence
6.4 Medium WPC Smart Compare for WooCommerce Plugin woo-smart-compare Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.4.6 CVE-2025-5530 Wordfence
4.3 Medium Order Delivery Date Pro for WooCommerce Plugin Information Disclosure Unauthenticated Arbitrary Post Title Disclosure No login needed 2.0 – < 12.6.0 Fixed in 12.6.0 CVE-2025-2942 WPScan
6.5 Medium WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 6.7.16 CVE-2025-3780 Wordfence
8.5 High Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration SQL Injection ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-24780 Patchstack
6.5 Medium Paytiko for WooCommerce Plugin paytiko Broken Access Control ≤ 1.3.21 CVE-2025-50032 Patchstack
9.8 Critical WooCommerce Product Multi-Action Plugin woo-product-multiaction PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.3 CVE-2025-49417 Patchstack
4.3 Medium WooCommerce Shop Page Builder Plugin dzs-wootable Broken Access Control ≤ 2.27.7 CVE-2025-29001 Patchstack
4.3 Medium Trust Payments Gateway for WooCommerce (JavaScript Library) Plugin trust-payments-gateway-3ds2 Cross-Site Request Forgery No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-53569 Patchstack
6.4 Medium PayMaster for WooCommerce Plugin woocommerce-paymaster-gateway-019 Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 0.4.31 CVE-2025-6729 Wordfence
6.5 Medium Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 8.0.2 Fixed in 8.0.3 CVE-2025-39362 Patchstack
7.2 High Amazon Products to WooCommerce Plugin import-products-to-wc Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 1.2.7 CVE-2025-5817 Wordfence
9.8 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin Arbitrary File Upload WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File Upload No login needed ≤ 1.7.1, 5.0 – 5.0.5 CVE-2025-5746 Wordfence
7.5 High WPB Category Slider for WooCommerce Plugin wpb-woocommerce-category-slider Local File Inclusion ≤ 1.71 CVE-2025-53281 Patchstack
7.1 High Additional Order Filters for WooCommerce Plugin additional-order-filters-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.22 Fixed in 1.23 CVE-2025-53271 Patchstack
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.148 Fixed in 1.2.149 CVE-2025-53203 Patchstack
7.1 High WPCRM - CRM for Contact form CF7 & WooCommerce Plugin wpcrm Cross-Site Scripting CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 CVE-2025-24774 Patchstack
8.1 High MBStore - Digital WooCommerce Plugin mbstore Local File Inclusion Digital WooCommerce WordPress Theme <= 2.3 - Local File Inclusion No login needed ≤ 2.3 CVE-2025-28947 Patchstack
7.1 High Woocommerce Line Notify Plugin woo-line-notify Cross-Site Scripting No login needed ≤ 1.1.7 CVE-2025-30972 Patchstack
10.0 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin drag-and-drop-file-upload-wc-pro Arbitrary File Upload WooCommerce plugin <= 5.0.6 - Arbitrary File Upload No login needed ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-49885 Patchstack
8.1 High Samex - Clean, Minimal Shop WooCommerce Theme samex Local File Inclusion Clean, Minimal Shop WooCommerce WordPress Theme <= 2.6 - Local File Inclusion No login needed ≤ 2.6 CVE-2023-25998 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only